The organization should keep a documented security survey procedure that: identifies assets and infrastructure, judges the countermeasures already in place and what a malicious, random or accidental disruption would cause; identifies interdependencies across disciplines and functions; identifies and profiles likely adversaries and threat agents, their capability, motive, tactics and chance of success; identifies likely targets and how attractive they are; finds vulnerabilities and rates their degree so countermeasure options can be identified and weighed; sets requirements for PPS and countermeasures and assesses their effectiveness, including operational and performance evaluation; works out risk scenarios from events that have happened or could happen, inside or outside, and their possible impact on assets, operations and functions; reports the risks, the evaluation methods used and how observations and recommendations are made; and supplies the facts on which PAP safeguards are developed, implemented and continued.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.