Requirement 0007 (Part One: Governance, section 2.1 Entity Protective Security Roles and Responsibilities; applies to All entities; dated 31 October 2024; retained from Release 2025): The Accountable Authority is responsible for managing the security risks of their entity. The Accountable Authority, supported by the CSO and CISO, determines risk tolerance, how risks are identified, assessed and prioritised, and considers impacts on other entities.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.