The organisation selects an assessor or team suited to the type of assessment, writes a control assessment plan covering the controls and enhancements assessed, the procedures used to judge effectiveness, and the environment, team and roles, has the plan approved by the authorizing official or a delegate before starting, assesses the controls at a set frequency to establish whether they are implemented correctly, operating as intended and producing the desired outcome against security and privacy requirements, produces an assessment report and gives the results to defined roles. The GC discussion calls for a privacy protocol or privacy impact assessment under the TBS standard where personal information is handled, with a published summary, and points to the TBS mandatory procedures for periodic control assessment. 3 enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.