The organization should maintain procedures for countermeasures that prevent and manage risks able to harm it, its assets, partners and stakeholders, so that it: meets legal and regulatory requirements; meets its obligations to internal and external stakeholders; delivers its PAP programmes (treatment and countermeasure plans); and meets what it aimed for in its PAP objectives and targets. Its controls ought to set out how it will: protect tangible and intangible assets adequately on the basis of the risk assessment; avoid, remove or lower the likelihood of an incident; lower and manage an incident's consequences; keep operations and services going; keep the controls intact if an incident happens; and recover afterwards. It should adopt layered protection (protection in depth) that cost-effectively deters, delays, detects and denies threats and supports response and recovery, considering layers that: eliminate exposure altogether; reduce risk by changing activities, processes, equipment or materials; isolate or separate assets from the risk; use engineered measures that deter a threat agent or hazard, slow it, detect it and deny it; use administrative measures (procedures, ways of working) that lower risk; and protect the asset where the risk cannot be removed or reduced. Asset value, the risk assessment, risk appetite and cost-benefit decide how many layers and of what kind, and interdependencies need evaluating because many physical countermeasures rely on electronic, telecommunications and information systems.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.