Requirement 0019 (Part One: Governance, section 3.1.1 Security Planning, Incidents and Training; applies to All entities; dated 31 October 2024; retained from Release 2025): The Accountable Authority approves the entity's security plan. The Accountable Authority approves the plan and its annual review; the CSO sets strategic direction and resourcing.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.