Security Testing Programme. RLEs must assess their risk and determine a suitable security testing programme (for example vulnerability assessment and penetration testing) commensurate with that risk (para 56).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.