Requirement 0011 (Part One: Governance, section 2.3 Entity Protective Security Roles and Responsibilities; applies to All entities; dated 01 July 2025; retained from Release 2025): A Chief Information Security Officer is appointed to oversee the entity's cyber security program and the cyber security for the entity's most critical technology resources. From 1 July 2025 a CISO oversees the cyber security program and the cyber security of the most critical technology resources, IT and OT, including the cyber strategy and uplift plan and implementation of the ISM; a CISO may sit in a shared-services entity if visibility is retained.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.