Achieved: all assets relevant to secure operation are inventoried at suitable detail and kept current; dependencies on supporting infrastructure such as power and cooling are recorded; assets are prioritised by importance to essential functions; responsibility is assigned for every asset, including physical ones; and assets are managed securely through their lifecycle to disposal. Not achieved includes partial inventories, unknown IT and OT dependencies, data kept without need or retention policy, and critical knowledge held by one or two people without succession.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.