Requirement 0020 (Part One: Governance, section 3.1.2 Security Planning, Incidents and Training; applies to All entities; dated 31 October 2024; retained from Release 2025): The security plan is considered annually and reviewed at least every two years to confirm its adequacy and ability to adapt to shifts in the entity's risk, threat or operating environment. Annual consideration decides whether updates are needed; a formal review at least every two years confirms adequacy and adaptation to changes in risk, threat level or business impact level.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.