The organization should run a PPS life-cycle programme on PDCA that keeps system objectives, sustainability and integrity intact, provides evidence of compliance and conformity, and records everything about the PPS and the PAPMS. Plan: from the risk assessment and objectives, justify the system, set its objective and requirements, fix the design criteria and the capacity, performance and design requirements, identify stakeholders and the competences needed, identify liability questions and legal requirements, and build the cost-benefit case and choose procurement methods. Do: design and deploy the system (equipment and hardware lists, software, schedules, drawings, specifications, schematics and contracting information), give training (operating and response procedures, manuals, schedules, plans, agendas and trainee assessments), decide who operates and who maintains the system, and set up installation, commissioning, testing, evaluation, acceptance and rejection. Check: set up testing through the life cycle, calibration, gathering and evaluating test data, warranty arrangements, reporting and record keeping, and planned upgrades, and the process for maintenance, evaluation and replacement. Act: watch changes in the threat and operating environment, find actual and potential control shortfalls and take corrective and preventive action, and identify improvements.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.