Requirement 0213 (Part Four: Technology, section 14.1 Cyber Security Strategies; applies to All entities; dated 01 July 2025; retained from Release 2025): The Chief Information Security Officer reports on the entity's cyber security risk at each meeting of the Audit Committee and biannually on the progress of the cyber security strategy and uplift plan. From 1 July 2025: cyber risk is reported at every meeting and uplift progress biannually, the latter as a written report.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.