Requirement 0008 (Part One: Governance, section 2.2 Entity Protective Security Roles and Responsibilities; applies to All entities; dated 31 October 2024; retained from Release 2025): A Chief Security Officer is appointed and empowered to oversee the entity's protective security arrangements. The CSO oversees the entity's protective security arrangements, tailored to scale, complexity and risk, may delegate day-to-day activity and fosters security awareness.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.