Require the Qualified Individual to report in writing, at least annually, to the board of directors, equivalent governing body, or senior officer responsible for the information security program. The report addresses overall program status, risk assessment, risk management decisions, service provider arrangements, testing results, security events, and recommendations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.