Per NCSC CAF Objective A: managing security risk. Requirements include (a) A.1 Governance + Roles and Responsibilities + Decision Making + (b) A.2 Risk Management Process + Assurance + (c) A.3 Asset Management + (d) A.4 Supply Chain.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.