The organization is required to define the PAPMS scope and boundaries (the whole organization or named parts) and keep it as documented information so it can be communicated clearly inside and outside. It is required to: set the PAP management requirements in light of its mission and goals, its obligations inside and outside the organization (stakeholder obligations among them) and its legal duties; allocate the critical operating objectives and the critical assets, functions, products and services; work out risk scenarios, drawn from events that have happened or could happen inside or outside, that could damage critical operations, functions and products; and frame the scope to suit its size, nature and complexity with improvement in mind. The scope has to keep the organization whole and protect its relationships with key suppliers, contractors, outsourcers, supply chain partners, customers, shareholders and the local community, and any outsourced process that affects conformity has to be kept under control.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.