Describe management's role in assessing and managing material risks from cybersecurity threats, addressing as applicable which management positions or committees are responsible and the relevant expertise of those persons or members in the detail needed to describe its nature (for example prior cybersecurity work experience, degrees or certifications, knowledge or skills); the processes by which they are informed about and monitor the prevention, detection, mitigation and remediation of cybersecurity incidents; and whether they report information about such risks to the board or a board committee or subcommittee. For a foreign private issuer with a two-tier board, the board is the supervisory board; for one relying on Rule 10A-3(c)(3), the board of auditors or statutory auditors.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.