Apply security risk management per NZISM Chapter 20 + ISO 31000 + NZ ISO/AS 31000:2018 covering risk identification + assessment + treatment + monitoring + governance reporting. Conduct vulnerability management and penetration testing per NZISM Chapter 21 including continuous scanning + risk-based patch management (Critical 14 days + High 30 days for SECRET+) + annual penetration test + Red Team exercises + vulnerability disclosure programme via CERT NZ. Report security incidents to NCSC + CERT NZ + Office of the Privacy Commissioner where personal information involved.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.