A responsible entity must report other cyber security incidents (with relevant impact on availability, integrity, or reliability) to the ACSC within 72 hours of becoming aware of the incident.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.