Requirement 0039 (Part Two: Risk, section 6.1 Third Party Risk Management; applies to All entities; dated 31 October 2024; retained from Release 2025): The entity is accountable for the management of security risks arising from procuring goods and services and ensures procurement and contract decisions do not expose the entity or the Australian Government to an unacceptable level of risk. Accountability for outsourced goods and services stays with the entity; where risks cannot be reduced to an acceptable level or quantified, alternative procurement is sought and the decision recorded. The CSO owns procurement security risk except cyber (the CISO).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.