Requirement 0042 (Part Two: Risk, section 6.1 Third Party Risk Management; applies to All entities; dated 31 October 2024; retained from Release 2025): Contractual security terms and conditions require service providers to report any actual or suspected security incidents to the entity, and follow reasonable direction from the entity arising from incident investigations. Providers report actual or suspected incidents to the entity and follow reasonable directions arising from investigations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.