The organisation develops security and privacy architectures describing the requirements and approach for protecting confidentiality, integrity and availability and for handling personal information to minimise privacy risk, how they integrate with the enterprise architecture, and assumptions and dependencies on external systems and services; reviews and updates them at a set frequency for enterprise architecture changes; and reflects planned changes in plans, CONOPS, criticality analysis, procedures and acquisitions. 2 enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.