The organisation categorizes the system and the information it processes, stores and transmits, documents the result with rationale in the system security plan, and has the authorizing official or delegate review and approve the categorization. The GC discussion asks for organisation-wide categorization involving the CIO, security, privacy, system, business and information owners, considering injury to other organisations and to national and non-national interests. 1 enhancement.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.