The organisation uses a formal sanctions process for individuals who fail to comply with security and privacy policies and notifies defined roles within a set time when a sanction process starts, naming the individual and reason. The GC discussion asks organisations to consult TBS on employee sanctions. No enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.