Operational Cyber Risk Management Programme. The objectives of the cyber risk policy must be delivered by an operational cyber risk management programme that defines, documents and communicates policies, processes and procedures (paras 15-16).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.