Requirement 0016 (Part One: Governance, section 2.5 Entity Protective Security Roles and Responsibilities; applies to All entities; dated 31 October 2024; retained from Release 2025): The Accountable Authority approves security governance arrangements that are tailored to the entity's size, complexity and risk environment. Governance arrangements are commensurate with size, complexity and risk; the audit committee under the PGPA Rule oversees risk including security risk.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.