Make the materiality determination for a cybersecurity incident without unreasonable delay after discovering it. Materiality follows the securities-law standard (a substantial likelihood that a reasonable shareholder would consider it important, or that it would significantly alter the total mix of information) and weighs quantitative and qualitative factors, such as harm to reputation, customer or vendor relationships or competitiveness, and the possibility of litigation or regulatory action. Because a cybersecurity incident includes a series of related unauthorized occurrences, related incidents that are each immaterial must be assessed collectively (C&DI 104B.09). An incident that has stopped must still be assessed (104B.05); insurance reimbursement of a ransom (104B.07) or a small payment (104B.08) does not by itself make it immaterial; consulting the Department of Justice or other agencies is not itself a materiality determination (104B.04).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.