Institutions shall take measures to mitigate identified ICT and security risks, including the protection measures in the information security section, and address residual risk in line with their risk appetite.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.