Documents the PAP process and this standard require should be controlled through one or more procedures that: approve documents as adequate before issue; review, update and re-approve them regularly and whenever an incident or a major operational change occurs; show changes and current revision status and make current versions available to the right users; confirm externally sourced information is suitable, reliable and controlled; set retention, archiving and destruction rules; keep originals and archive copies of documents, data and information legible and easy to identify; identify and control the distribution of external documents needed for planning and operating the PAP process; mark as obsolete any outdated documents that must be kept; and protect document integrity by making them tamper-proof, backing them up securely, restricting access to authorised people and shielding them from damage, decay or loss. The organization should also classify information by proprietary and security sensitivity and act to stop unauthorised access.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.