A positive cyber security culture and shared responsibility are developed. Partially achieved: executives understand and communicate its importance, expected behaviours are described, people know their contribution and how to raise issues, and barriers to secure behaviour are addressed. Achieved: executives communicate priorities clearly, raising incidents is treated positively and recognised, management is visibly involved, communication is open, and people collaborate on security improvements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.