The organization should run one or more strategic PAP programmes, optimised and prioritised to control risks from threats, hazards and disruption to the organization and to its supply chain partners. The programmes should include: who is accountable and responsible and what resources are assigned at each relevant function and level; the business, operational and environmental needs, the assets, activities, functions and processes, regulatory and legal requirements, contract obligations and stakeholder needs taken into account; how and by when results are to be achieved; for the PAP systems, their objectives and design criteria, required performance, how they are bought and put in, and how they are managed over their life; and alignment with organization-wide risk management criteria and strategy. It should also check whether the programmes have delivered cost-effective protection, created new risks, or strengthened or weakened the protection systems, review them periodically for continued effectiveness and fit with objectives, and amend them where needed.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.