The organisation establishes policy and procedures ensuring that requirements to protect controlled information processed, stored or transmitted on external systems are implemented as required by law and policy, and reviews and updates them at a set frequency. The GC discussion defines controlled information as Protected A, Protected B and unclassified controlled goods information and points to the TBS security categorization standard, the Privacy Policy, the PSPC Contract Security Manual chapter 6 and Annex C, and TBS guidance on information sharing agreements. No enhancements. Deployed organisation-wide in the medium profile.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.