The organisation determines high-level security and privacy requirements for the system or service in mission and business planning, determines, documents and allocates the resources to protect it through capital planning and investment control, and sets a discrete line item for security and privacy in programming and budgeting documents. No enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.