Entities must implement security management structures and processes that integrate protective security into governance, risk, planning, and assurance activities, including reporting to the Accountable Authority.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.