Requirement 0115 (Part Four: Technology, section 15.4 Cyber Security Programs; applies to All entities; dated 31 October 2024; retained from Release 2025): A vulnerability disclosure program and supporting processes and procedures are established to receive, verify, resolve and report on vulnerabilities disclosed by both internal and external sources. Processes receive, verify, resolve and report on vulnerabilities disclosed by internal and external sources on a responsible-disclosure basis.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.