Every information system manager must protect its systems under the Law, connect its cybersecurity monitoring and centralised anti-malware systems to the Ministry of Public Security's National Cybersecurity Centre or the provincial centre, and report cybersecurity incidents to the specialised agency of the Ministry of Public Security or of National Defence; under Decree 333 it must organise self-monitoring and warning mechanisms and support the specialised force's monitoring. Managers using the state budget must have their protection plan appraised when building or upgrading a system and designate a person or unit responsible for cybersecurity.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.