Security and resilience policies, processes and procedures are developed and improved to manage risk to essential functions. Partially achieved: they document governance, risk management, technical practice and regulatory compliance and are updated after major incidents. Achieved: they are fully documented, embed security with key indicators reported to executives, are practical and usable, rely on users only where achievable, are reviewed at suitable intervals and on changes to the function or threat, and systems stay secure even when users do not follow procedures.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.