Requirement 0201 (Part Six: Physical, section 25 Physical Security Measures and Controls; applies to All entities; dated 31 October 2024; retained from Release 2025): Physical security measures are implemented to protect entity resources, commensurate with the assessed business impact level of their compromise, loss or damage. Protection is scaled to the assessed impact of compromise, loss or damage.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.