The organisation includes in acquisition contracts for systems, components or services, explicitly or by reference and using standard or defined contract language, the security and privacy functional requirements, strength of mechanism requirements, assurance requirements, controls needed, documentation requirements and their protection, a description of the development and operating environments, the allocation of responsibility for security, privacy and supply chain risk management, and acceptance criteria. The GC discussion points to the PSPC Supply Manual on privacy in contracting and TBS guidance on ownership, accuracy, secondary use limits, disposition and return of records, audit rights, breach and complaint mechanisms, and legal disclosure. 12 enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.