Reduce the risk of exploitation of unpatched systems by ensuring application of security patches and updates on Information Technology and Operational Technology systems with documented timelines, exception handling and compensating controls where patching is not feasible.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.