Staff Cyber Risk Awareness Training. Staff cyber risk awareness training must be completed at least annually, with additional training for staff in roles responsible for cyber risk (para 47).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.