The organization should keep documented performance criteria and procedures for situations where lacking them could cause drift from what the PAP policy, objectives and targets set out, covering, as relevant, how PPS are designed, bought, installed, run, maintained, assessed and replaced, and should assess the risks of revised or new arrangements before introducing them. Operational control procedures should define: purpose and scope; objectives and measures of success; implementation steps, phasing and sequence; roles, responsibilities and authorities; technology requirements, including maintenance and calibration; communication requirements and procedures; internal and external interdependencies and interactions; resource needs; and information flow and documentation. The procedures should make sure that: demand signals are reflected in capacity planning; contingencies and redundancies give protection in depth; supplier responses are validated (for example recovery times for a site, process or product); there is feedback on whether earlier controls are changing through design, engineering or process changes or outsourcing decisions; planned changes are controlled and unplanned ones reviewed and acted on; and procedures are reviewed periodically, with the PPS revised and documented where needed.
This control maps to 3 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.