Entities must develop and implement a security plan informed by an enterprise security risk assessment, addressing risks across information, personnel, and physical security, and reviewed at least annually.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.