Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct
BMA Code Section VI: Detect and Protect Controls

Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct BMA-21: Security Testing Programme

Security Testing Programme. RLEs must assess their risk and determine a suitable security testing programme (for example vulnerability assessment and penetration testing) commensurate with that risk (para 56).

Other controls in BMA Code Section VI: Detect and Protect Controls

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.