Requirement 0014 (Part One: Governance, section 2.4 Entity Protective Security Roles and Responsibilities; applies to All entities; dated 31 October 2024; retained from Release 2025): Where appointed, security practitioners are appropriately skilled, empowered and resourced to perform their designated functions. Where the CSO or CISO delegate day-to-day protective security to practitioners, those practitioners must be able to perform their functions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.