Requirement 0098 (Part Four: Technology, section 14.1 Cyber Security Strategies; applies to All entities; dated 01 July 2025; retained from Release 2025): A cyber security strategy and uplift plan is developed, implemented and maintained to manage the entity's cyber security risks in accordance with the Information Security Manual and the Guiding Principles to Embed a Zero Trust Culture. From 1 July 2025 the strategy follows the ISM and the five Guiding Principles to Embed a Zero Trust Culture: enterprise-level cyber risk, clear accountabilities, knowing critical assets, resilience through strategy and uplift plans, and incident planning beyond preparation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.