Per AUPA 2024 enhancing APP 11: technical and organisational measures. Requirements include (a) implement enhanced Technical and Organisational Security Measures clarifying reasonable steps + (b) implement encryption + access control + activity logging + (c) conduct regular security testing aligned to Essential Eight + ISM + (d) maintain documented security baseline + (e) align with NDB Scheme breach handling + (f) integrate with broader InfoSec.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.