Providers shall conduct annual information security risk assessments covering assets within the certification scope, with risks treated through controls or formally accepted by management, and the risk register reviewed periodically.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.