Entities must ensure that ICT systems holding official information are governed in accordance with the Information Security Manual, with documented authorisation to operate by the Accountable Authority or delegate.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.