Requirement 0198 (Part Six: Physical, section 24.2.2 Security Zones; applies to All entities; dated 31 October 2024; retained from Release 2025): Security Zones One to Five are accredited by the Accreditation Authority before they are used operationally, on the basis that the required security controls are certified and the entity determines and accepts the residual risks. The CSO or delegate accredits once controls are certified and residual risks accepted (Table 41); recertification follows expiry, business impact changes, significant architecture or control changes or accreditation conditions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.