IT Audit Plan. The third line of defence, IT audit, should provide the audit committee of the board (or equivalent) with independent assurance over the cyber risk programme through a risk-based IT audit plan (para 23).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.