After incidents the organisation understands causes to inform remediation. Achieved: post-incident analysis is routine and considers organisational, technical and human factors and threat changes; all relevant incident data is available to analysts; and plausible alternative ('what if') circumstances are considered. Not achieved includes no root cause process, confirmation bias in investigations, and investigations aimed only at blaming individuals.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.