The organisation implements a process ensuring that plans for security and privacy testing, training and monitoring of its systems are developed, maintained and executed, and reviews those plans for consistency with the risk management strategy and response priorities. No enhancements. Deployed organisation-wide in the medium profile.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.