Requirement 0211 (Part Four: Technology, section 13.2.1 Technology Lifecycle Management; applies to All entities; dated 01 July 2025; retained from Release 2025): A Technology Asset Stocktake and Technology Security Risk Management Plan is created to identify and manage the entity's internet-facing systems or services to ensure continuous visibility and monitoring of the entity's resource and technology estate. From 1 July 2025 (Direction 002-2024 integrated): internet-facing systems, services and devices are identified for continuous visibility and monitoring; network documentation shows connections, critical and high-value servers and device settings and is itself protected.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.