The company must document a threat assessment covering deliberate contamination or damage, whether from inside or outside the organisation. From it the company must produce a written food defence plan, kept under review as circumstances and market intelligence change, formally reviewed at least once a year and whenever a new risk appears or an incident suggests product security has been compromised, and meeting any legal requirements that apply where the product will be sold.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.