Per Papua New Guinea National Cybersecurity Policy and Cybercrime Act: critical infrastructure protection + national cybersecurity governance. Requirements include (a) identify + classify critical information infrastructure including telecommunications + energy + financial + government services + transport + health systems + (b) implement Critical Infrastructure Protection measures including defined responsibilities + assessment + monitoring + (c) align to National Cybersecurity Framework and Governance structures including NICTA (National Information and Communications Technology Authority) oversight + national CERT coordination + (d) integrate organisational cybersecurity with national governance including reporting + cooperation + (e) maintain documentation supporting national-level assessments + (f) align security baselines and assessments with the National Cybersecurity Policy.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.