A participant must have adequate arrangements to ensure the resilience, reliability, integrity and security of its critical business services, covering their identification, risk management, scalable capacity, prevention of unauthorised access, change, major events and outsourcing; review them after each material change and at least every 12 months; and document the arrangements and reviews for seven years.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.