An up-to-date incident response plan is grounded in a thorough risk assessment of essential-function systems and covers a range of scenarios. Partially achieved: the plan covers those systems and likely impacts of known attacks, is understood by the response staff, documented and shared, accessible even when IT is compromised, and regularly reviewed. Achieved: the plan rests on clear understanding of risk, covers the full incident lifecycle, roles and reporting and both known and previously unseen attacks, is integrated with business, supply chain and supporting infrastructure plans, and is understood by the business areas running the essential function.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.