Requirement 0110 (Part Four: Technology, section 15.2 Cyber Security Programs; applies to All entities; dated 31 October 2024; retained from Release 2025): Entities consider IRAP assessment recommendations and findings, and implement on a risk-based approach. Entities consider findings and implement recommendations as risk warrants.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.