Vulnerabilities shall be identified through regular scanning, prioritised by severity and exposure, and remediated within timeframes specified in policy, with emergency patching procedures for critical zero day issues.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.