The organisation understands threat actors' capabilities, methods and likely targets and uses this to shape risk decisions and defences (new in v4.0). Partially achieved: threat analysis of common threats and attack types, kept current, anticipating targets, informed by common incidents and applied to risk decisions. Achieved: detailed analysis in the context of the sector and national infrastructure, including capable well-resourced actors; viewing systems from an attacker's perspective, developing plausible scenarios, mapping the steps an attacker must take and justified measures at each step; maintaining current intelligence; and documenting the analysis method.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.