Management shall establish an information security management system, define the scope, set the security strategy and provide adequate resources to implement IT-Grundschutz methodology.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.