Top management is required to lead the security management programme by: setting a physical asset protection (PAP) management policy; naming one person answerable for the PAPMS who holds the authority and competence to be accountable for putting it in place, keeping it running and evaluating it; telling the organization why meeting PAP objectives, following the policy, meeting legal obligations and improving continually matter; giving enough resources and time for the PAPMS to be set up, operated, watched, reviewed, kept current and improved (specialist staff, equipment and in-house infrastructure, technology and information, processes, and funding); setting the risk criteria and risk appetite; and holding management reviews of the PAPMS regularly.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.