Apply Govern-P function including: Governance Policies (GV.PO-P) covering policies + responsibilities + roles + legal/regulatory requirements + privacy risk in governance; Risk Management Strategy (GV.RM-P) covering risk tolerance + ecosystem-informed risk; Awareness and Training (GV.AT-P) covering workforce training + role-based + privileged user + third-party awareness; and Monitoring and Review (GV.MT-P) covering programme monitoring + effectiveness review + privacy values incorporated + workforce informed + processes improvements. Integrate with NIST CSF 2.0 GOVERN function.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.