Article 48 establishes the INFORMATION PROTECTION regime for sensitive electricity-grid + cybersecurity information shared under NCCS. Information is classified at one of four levels: (1) PUBLIC; (2) RESTRICTED; (3) CONFIDENTIAL; (4) HIGHLY CONFIDENTIAL. Each level has specific handling + storage + transmission + access-control requirements. Article 49 establishes the access-rights regime: only persons with a documented 'need-to-know' + appropriate security clearance (where applicable) may access classified NCCS information. Article 50 sets the security-clearance requirements for personnel handling CONFIDENTIAL + HIGHLY CONFIDENTIAL information including TS or equivalent national clearance. Information-protection requirements apply to both transit + at-rest + cross-border sharing scenarios.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.