Key IT staff are identified, and dependence on one person to carry out any critical role is kept as low as possible by capturing and sharing knowledge, planning succession and providing backup staff. Guidelines require key people to take a minimum amount of leave each year as a security precaution; suitable steps are taken when people change jobs and above all when they leave; documentation, knowledge sharing, succession planning, backup, cross-training and job rotation cut the reliance on single individuals; and backup arrangements for staff are tested regularly.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.