Requirement 0054 (Part Two: Risk, section 8.2 Contingency Planning; applies to All entities; dated 31 October 2024; retained from Release 2025): Decisions to implement an alternative mitigation measure that meets or exceeds a PSPF requirement or standard are reviewed and reported annually. An alternative mitigation achieves the same or better protection than the requirement; the decision is documented in the security plan and reported as 'risk managed'.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.