Requirement 0026 (Part One: Governance, section 3.6.1 Security Planning, Incidents and Training; applies to All entities; dated 31 October 2024; retained from Release 2025): Procedures are developed, implemented and maintained to ensure security incidents are responded to and managed. The CSO, with the CISO for cyber incidents, establishes an incident management plan with consequence management and exercises it; a security incident includes failures to meet requirements, attempts at unauthorised access, approaches seeking access and harmful events.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.