Asset owners establish, implement and maintain a documented Cyber Security Management System covering scope, policy, risk analysis, risk treatment, training, business continuity, physical security, network segmentation, access control, monitoring, incident response and management review specific to IACS environments.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.