The organisation gives individuals needing system access rules describing their responsibilities and expected behaviour for information and system use, security and privacy, obtains their documented acknowledgement before granting access, reviews and updates the rules at a set frequency, and requires re-acknowledgement at a set frequency and, or, when the rules change. The GC discussion allows rules for external users or recipients to be set in an information sharing agreement or arrangement. 1 enhancement.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.