Chief Information Security Officer (CISO). A CISO with the necessary experience and competencies must be appointed to deliver the operational cyber risk management programme (paras 17-18).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.