The organisation is prepared to restore essential functions after adverse impact to systems. Partially achieved: all systems and technologies needed for restoration and their interdependencies are known, as is the recovery order. Achieved: business continuity and disaster recovery plans are tested for practicality, effectiveness and completeness by varied methods (fail-over, table-top, red teaming), and threat intelligence triggers immediate temporary security measures when risk rises.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.