Regulations 5 and 6 require medium and high-tier database owners to conduct a risk assessment at least every 18 months identifying threats to confidentiality, integrity, and availability. High-tier databases must also undergo penetration testing at least every 18 months. Findings must be reported to the database manager and remediated under a tracked plan.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.