Within the period specified by the Rules, the responsible entity must adopt and maintain compliance with one of the recognised cyber security frameworks for the cyber and information security hazard, such as the ACSC Essential Eight (Maturity Level One), ISO/IEC 27001, the NIST Cybersecurity Framework, the AESCSF framework core, or an equivalent recognised framework, and maintain it as the cyber baseline for the asset.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.