Requirement 0018 (Part One: Governance, section 3.1 Security Planning, Incidents and Training; applies to All entities; dated 31 October 2024; retained from Release 2025): A security plan is developed, implemented and maintained to address the mandatory elements of the plan. Table 1 elements: goals and objectives, security risk environment, risk tolerance, security capability, risk management strategies, implications of risk decisions for others, PSPF implementation, Directions, critical people and resources, threat levels (National Terrorism Threat Level and ASIO reporting), incident management plan, monitoring and improvement, and review. Large entities may use an overarching plan with supporting plans approved by the CSO or CISO.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.