The organisation understands the data important to essential functions, where it is held and travels, and the impact of its loss, compromise or unavailability, including at third parties. Partially achieved: important data and data useful to attackers are catalogued with who can access them, location and quality are reviewed, mobile devices and media holding them are identified, and impact scenarios are documented and occasionally validated. Achieved additionally: current understanding of location, quantity, quality and data links, removal of unnecessary copies and historic data, understanding of context and dependencies, and impact statements validated at least annually.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.