Requirement 0023 (Part One: Governance, section 3.4 Security Planning, Incidents and Training; applies to All entities; dated 31 October 2024; retained from Release 2025): The Accountable Authority and Chief Security Officer develop, implement and maintain a program to foster a positive security culture in the entity and support the secure delivery of government business. The Accountable Authority and CSO are responsible for a program in which personnel value, use and protect information and resources, supported by the CISO and practitioners.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.