The entity must be able to detect, respond to and report cyber security incidents affecting its systems, including reporting to Defence and the ACSC as required.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.