After full implementation, the organization should periodically assess how effective the program is and update its policies, procedures, training, approaches and protocols where required, looking at: how well the Threat Management Team works, including its make-up, training and participation; failures, successes and difficulties in handling individual reports that point to changes in protocols; how many reports come in, of what kind, and related measures, to direct resources where needed; changing legal, regulatory or contractual requirements calling for revision; failures, successes, lessons and difficulties in building WVPI into training and culture; and further training or prevention measures the organization can now take on.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.