Internal and external stakeholders should be communicated with and consulted at every stage of the PAPMS, through a formal documented process that makes sure: risks and obligations are properly identified; stakeholder interests and dependencies on internal and external resources and parties are understood; the PAPMS links up with other management disciplines; stakeholder needs are weighed when risk criteria are set and risks evaluated; PPS design, implementation and evaluation are done by qualified, approved PAP professionals; the work stays within the right internal and external context, including the codes of practice and industry standards of the region; and proven, tested ways of communicating and consulting work in both normal and abnormal conditions. Where top management chooses not to share sensitive information (to avoid alarm or for information security reasons), the reasons should be written down.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.