Requirement 0089 (Part Four: Technology, section 13.3 Technology Lifecycle Management; applies to All entities; dated 31 October 2024; retained from Release 2025): A register of the entity's authorised technology systems is developed, implemented and maintained, and includes the name and position of the Authorising Officer, system owner, date of authorisation, and any decisions to accept residual security risks. The register records the Authorising Officer's name and position, system owner, authorisation date and residual risk acceptances.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.