The organization shall set down a cybersecurity policy recognising the cybersecurity risks of road vehicles and records the commitment of executive management to managing those risks; the policy may connect to the organization's objectives and to its other policies, and it may state how generic threat scenarios are treated across the product range.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.