The organisation has justified confidence in the effectiveness of security across technology, people and processes. Achieved: security measures are validated as effective throughout their lifetime, assurance methods are understood and chosen appropriately, confidence can be justified to and verified by a third party, deficiencies are prioritised and fixed promptly, and assurance methods are themselves reviewed. Not achieved includes treating a product as a silver bullet, taking vendor claims at face value, or assuming assurance from the absence of known problems.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.