The organisation develops a comprehensive strategy to manage security risks from operating and using its systems and privacy risks to individuals from authorized handling of personal information, implements it consistently across the organisation, and reviews and updates it at a set frequency or when organisational changes require. No enhancements. Deployed organisation-wide in the medium profile.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.