Requirement 0021 (Part One: Governance, section 3.2 Security Planning, Incidents and Training; applies to All entities; dated 31 October 2024; retained from Release 2025): Procedures are developed, implemented and maintained to ensure all elements of the entity's security plan are achieved. Practices and procedures cover all elements of protective security; the CSO owns them except cyber, which the CISO owns.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.