Requirement 0107 (Part Four: Technology, section 14.2.9 Cyber Security Strategies; applies to All entities; dated 31 October 2024; retained from Release 2025): The remaining mitigation strategies from the Strategies to Mitigate Cyber Security Incidents are considered and, where required, implemented to achieve an acceptable level of residual risk for their entity. Prioritise by threat (targeted intrusions, ransomware and destructive actors, malicious insiders) and implement first for high-risk users and computers; alternative standards such as ISO/IEC 27001 are not an authorisation pathway and reliance on them is reported.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.