IT Security Incident Management. A formal IT security incident response process must be established, with consideration of a computer security incident response team, post-incident root-cause review, defined crisis escalation, and annual tabletop exercises (paras 36-40).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.