Security policies are implemented and their benefits can be shown. Partially achieved: most are followed and monitored, integrated with HR trustworthiness assessments, staff know their responsibilities, and significant breaches are investigated while others are tracked for trends. Achieved: all are followed with application and effectiveness evaluated, they are communicated at every level, and all breaches with potential to affect the essential function, including aggregated ones, are acted on.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.