Requirement 0139 (Part Five: Personnel, section 17.3.2.2 Access to Resources; applies to All entities; dated 31 October 2024; retained from Release 2025): Personnel are not granted approval to work remotely in locations where Australian Government information, or resources are exposed to extrajudicial directions from a foreign government that conflict with Australian law, unless operationally required, and the residual risks are managed and approved by the Chief Security Officer. ASIO provides country-specific threat assessments; exceptions require operational need and CSO approval of residual risk.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.