All organisations must proactively prevent, detect and block malware; managers must apply technical measures against the listed attack types and review systems to remove cyber-terrorism risks; email, transmission and storage service providers must filter malware in sending, receipt and storage and report as the law requires; Internet service providers must stop malware spreading and act on authorities' requests; critical-system managers must deploy dedicated anti-malware systems.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.