Response plans are exercised using past incidents at the organisation and elsewhere and scenarios drawn from threat intelligence and risk assessment. Achieved: scenarios are based on real incidents, experience or intelligence, documented, reviewed and validated; exercises run routinely with findings used to refine plans and protective security; and they test the whole response cycle including restoration of normal operation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.