Set policies and procedures for judging how well the cyber risk management measures work, for example through audits, and for reviewing and updating the measures at intervals.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.