Operate a Cybersecurity Incident Response Team (CSIRT) capability covering 24/7 monitoring, triage, containment, eradication, and recovery for CII and licensed operators. Notify the Central Body for Cyber Security and MoTC within statutory windows (typically 24 hours for material incidents, 72 hours for personal data breaches). Coordinate with mmCERT (Myanmar Computer Emergency Response Team) during cross-sector incidents. Conduct annual incident response tabletop exercises and maintain post-incident root cause analyses for at least 5 years.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.