Those within scope must take the cybersecurity measures that the legislation prescribes for national security, public order or the proper conduct of public services. The measures are set in secondary regulation and in the Presidency's procedures, standards and minimum criteria (Articles 5(1)(e), 5(1)(g), 6(1)(h) and 6(1)(ı)); until the Law's implementing regulations enter into force, existing regulations continue to apply insofar as they do not conflict with the Law (Provisional Article 1(6)). Failing the duty carries an administrative fine of 1 million to 10 million Turkish lira (Article 16(10)), and a person who causes a data breach by acting against the requirements of their duty to protect critical infrastructure against cyber attack faces one to three years' imprisonment (Article 16(9)).
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.