Providers shall maintain a documented information security policy framework approved by senior management, with policies, standards, and procedures covering all CSAP control domains and reviewed at least annually.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.