Conduct a review of the cyber security program at least every 24 months, including an evaluation of the effectiveness of the program in protecting Critical Digital Assets, with results documented and findings tracked to closure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.