A firm must identify and document the people, processes, technology, facilities and information needed to deliver each important business service, in enough detail to find and fix vulnerabilities (including those at third parties it relies on), and review the mapping on material change and at least annually.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.