Requirement 0038 (Part Two: Risk, section 5.2 Security Risk Management; applies to All entities; dated 31 October 2024; retained from Release 2025): The Accountable Authority considers the impact that their security risk management decisions could potentially have on other entities, and shares information on risks where appropriate. The plan records how risk-management decisions are shared with entities that are or may be affected.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.