Cloud service providers shall maintain documented incident response procedures with defined severity tiers, notification to affected government customers and KISA within prescribed timeframes, and post incident review with corrective actions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.