Requirement 0090 (Part Four: Technology, section 13.3.1 Technology Lifecycle Management; applies to All entities; dated 31 October 2024; retained from Release 2025): Each technology system's suitability to be authorised to operate is reassessed when it undergoes significant functionality or architectural change, or where the system's security environment has changed considerably. Triggers include changes to ISM controls or policy, new threats, ineffective controls, major incidents and major functional or architectural change; system owners monitor that risk stays within tolerance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.