The policy should state how much risk the organisation is willing to take, how it views risk and how it manages it, set responsibilities throughout the organisation and refer to any legally required policy statements, for example on health and safety. A joined-up toolkit supports each stage of the process, which needs the backing of the chief executive and the executive team, assigned responsibilities and resources for training and building risk awareness among all stakeholders.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.