Effective internal processes manage and communicate risks to essential-function systems (achieved, partially achieved or not). Partially achieved: risks are identified, analysed, prioritised and managed using an understanding of known threats and vulnerabilities, outputs are clear security requirements, conclusions reach accountable people, and assessments are redone on significant events. Achieved additionally: risk is framed around adverse impact to essential functions and how threat actions could cause it; assessments rest on clear, current threat assumptions and vulnerability knowledge; requirements are traceable and prioritised; assessments are dynamic; the process is reviewed and improved; and emerging technologies are anticipated.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.