Entities must monitor and report their security maturity against PSPF outcomes annually to the Attorney-General's Department, including against Essential Eight cyber controls where applicable.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.