All security policies and operational procedures that are identified in Requirement 8 are: • Documented. • Kept up to date. • In use. • Known to all affected parties
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.