Operate event logging and monitoring per NZISM Chapter 13 covering security event logging + log retention (3-year minimum for SECRET + 7-year for TOP SECRET) + SIEM aggregation + 24x7 SOC monitoring. Maintain Incident Response Plan per NZISM Chapter 14 including detection + containment + eradication + recovery + lessons learned + NCSC notification within agreed timeframes + CERT NZ coordination. Maintain Business Continuity and Disaster Recovery per NZISM Chapter 15 including BCP + DRP + annual testing + RTO/RPO targets.
The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.