Canada-specific control: the organisation requires its business function to run a sovereignty and jurisdiction threat and risk assessment at the selected organisation, mission or system level that assesses the maximum injury from external legal compulsion of business functions or information assets (considering business needs for security including laws requiring non-disclosure, updating the security categorization, and documenting the consequences of compulsion), performs a jurisdiction-specific threat assessment of the likelihood of being targeted, assesses how the foreign jurisdiction could exploit the functions or assets, and completes a jurisdiction-specific risk assessment. The GC discussion cites the TBS Directive on Service and Digital requirement that Protected B and C data be located in Canadian jurisdiction as the principal option, and the Cyber Centre recommendation to keep all significantly sensitive data and functions in Canada. 9 enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.