The organisation conducts a risk assessment identifying threats and vulnerabilities, the likelihood and magnitude of harm from unauthorized access, use, disclosure, disruption, modification or destruction, and the likelihood and impact of adverse effects on individuals from handling personal information; integrates organisation and business-level risk results with system assessments; documents results in the plans or a report; reviews and disseminates them; and updates the assessment at a set frequency or on significant change. The GC discussion adds human, signals and imagery intelligence to all-source intelligence. 4 enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.