Alerts are placed in context of threat and system knowledge to identify incidents and each is handled appropriately. Partially achieved: alerts from some tools are triaged and acted on, playbooks cover common cases and are reviewed, some triage actions are recorded, alerts are categorised by type and severity, and understanding of normal behaviour informs triage. Achieved: alerts from all tools triaged, playbooks cover all plausible cases, all triage is documented and drives improvement, triage enables prioritised follow-up such as containment, and understanding of normal behaviour and threats is sufficient for effective decisions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.