CSF 2.0 Category: cybersecurity roles, responsibilities and authorities to foster accountability, performance assessment and continuous improvement are established and communicated. Priority Medium. R1: cybersecurity roles, responsibilities and authorities should include incident response. The recommendation applies to every GV.RR Subcategory (GV.RR-01 to GV.RR-04).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.