Regularly test or otherwise monitor the effectiveness of the safeguards key controls, systems, and procedures. Testing must include continuous monitoring or, in its absence, annual penetration testing and biannual vulnerability assessments.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.