Threats and corresponding user and system behaviour are understood well enough to detect incidents (new in v4.0, replacing the v3.2 anomaly-based outcomes). Partially achieved: effectiveness of threat intelligence is known, intelligence services are used, abnormalities from past attacks and intelligence signify adverse activity, and detection tools receive regular updates. Achieved: effectiveness tracked and feedback shared with providers and the defender community, feeds chosen on risk and sector needs, actionable intelligence delivered promptly and contextualised, normal behaviour understood so anomaly searching is effective, monitored abnormalities based on likely adverse activity and kept current, and capability to share intelligence with sector partners and government.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.