Per Australian Protective Security Policy Framework (PSPF) Release 2024 Governance: security culture + governance. Requirements include (a) develop + maintain Security Culture across entity + (b) implement Security Risk Management including identification + treatment + (c) integrate with enterprise risk management + (d) maintain Chief Security Officer (CSO) role + governance + (e) implement security planning + reporting + (f) cooperate with Commonwealth Security Advisor + AGSVA.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.