Agencies should not obtain off-site IT services and functions from industry providers based in countries with which New Zealand lacks a multilateral or bilateral security agreement covering protection of New Zealand government classified information. Where there is doubt, the agency's CISO should be consulted.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.