The CIRMP must establish and maintain a process or system to identify, and as far as reasonably practicable minimise or eliminate, material risks arising from cyber and information security hazards, and to mitigate their relevant impact on the asset.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.