The organisation defines its mission and business processes with consideration for security and privacy and the resulting risk, determines the information protection and personal information handling needs arising from them, and reviews and revises the processes at a set frequency. No enhancements. Deployed organisation-wide in the medium profile.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.