Evaluate and adjust the information security program in light of the results of the testing and monitoring, any material changes to operations or business arrangements, the results of risk assessments, or any other circumstances that may have a material impact on the program.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.