Systems on the Prime Minister's list of systems critical to national security (energy, finance, banking, telecoms, transport, health and other national systems, among others) must pass cybersecurity appraisal and be certified as meeting conditions before operation. Their managers must inspect before putting new or upgraded systems into use, self-inspect and assess conditions each year and report the results in writing to the specialised force before October, monitor continuously with that force, keep emergency and incident response plans and report incidents, and assign dedicated qualified personnel with regular training.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.