Requirement 0036 (Part Two: Risk, section 5.1 Security Risk Management; applies to All entities; dated 31 October 2024; retained from Release 2025): The Accountable Authority determines their entity's tolerance for security risks and documents in the security plan. Risk tolerance covers expectations for mitigating, accepting and pursuing risk, thresholds of acceptable risk and consequences for acting beyond them, recorded in the security plan.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.