The organisation manages the security and privacy state of its systems and environments through authorization processes, designates individuals for specific risk management roles, and integrates authorization into an organisation-wide risk management program. No enhancements. Deployed organisation-wide in the medium profile.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.