The organisation implements a process ensuring that plans of action and milestones for the security, privacy and supply chain risk management programs and their systems are developed and maintained, record the remedial actions responding to risk, and are reported as required, and reviews them for consistency with the risk management strategy and organisation-wide priorities. The GC discussion notes they are subject to TBS reporting. No enhancements. Deployed organisation-wide in the medium profile.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.