The service organization identifies risks to the achievement of its objectives and analyzes risks as a basis for determining how the risks should be managed.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.