Establish, submit and maintain a Cybersecurity Assessment Plan that proactively assesses the effectiveness of the approved Cybersecurity Implementation Plan, including objective assessment of at least one third of the policies, procedures, measures and capabilities each year so that all are assessed within a three year period.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.