Categories B and C (as an alternative to independent certification) and category D (mandatory; optional consideration for E) self-assess against an approved standard: the ISM, ISO/IEC 27001 or 27002 (2022 editions in the questionnaire), ISO/IEC 27017, SOC 2, OWASP ASVS (to Level 2 at least) or NIST CSF (NIST not available to category A), or another standard the DPO accepts case by case. The self-assessment determines which controls apply, answers the full control suite with how each is met or why it does not apply, covers the policies, procedures and data repositories holding in-scope data, is reviewed annually and resubmitted every two years, and is revised and resubmitted as soon as possible after a significant change. A statement of applicability against ISO/IEC 27002:2022 is acceptable evidence for ISO/IEC 27001 self-assessment. One self-assessment may cover several products if the DSP attests each is covered.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.