The organisation develops and disseminates an organisation-wide information security program plan that gives an overview of the program's requirements and the program management and common controls in place or planned, identifies and assigns roles, responsibilities, management commitment, coordination and compliance, reflects coordination among the entities responsible for information security, and is approved by a senior official accountable for the risk; it reviews and updates the plan at a set frequency and after defined events, and protects it from unauthorized disclosure and modification. No enhancements. Deployed organisation-wide in the medium profile.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.