Requirement 0086 (Part Four: Technology, section 13.3 Technology Lifecycle Management; applies to All entities; dated 31 October 2024; retained from Release 2025): The Authorising Officer authorises each technology system to operate based on the acceptance of the residual security risks associated with its operation before that system processes, stores or communicates government information or data. Authorising Officers per Table 21: the Accountable Authority or CISO (or delegate) of the system owner up to SECRET, the ASD Director-General for TOP SECRET; assessors are entity assessors or IRAP assessors, ASD for TOP SECRET; the same framework applies to outsourced systems, cloud services, gateways and AI technologies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.