Requirement 0009 (Part One: Governance, section 2.2 Entity Protective Security Roles and Responsibilities; applies to All entities; dated 31 October 2024; retained from Release 2025): The Chief Security Officer is a Senior Executive Service officer and holds a minimum security clearance of Negative Vetting 1 (an entity with fewer than 100 employees may appoint an EL2 who reports directly to the Accountable Authority on security matters). The CSO is Senior Executive Service and holds at least a Negative Vetting 1 clearance; entities with fewer than 100 employees may appoint an EL2 CSO who reports directly to the Accountable Authority on security and has sufficient authority and capability.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.