Suppliers are selected through a fair and formal practice for a viable best fit to specified requirements, with the requirements optimised from potential suppliers' input: requests for information and proposals clearly define requirements including security and privacy, operational business processes, deliverables, warranties and legal terms; they are evaluated under the approved process and criteria with documentary evidence and reference checks; the best-fitting vendor is selected, the decision documented and communicated and the contract signed; for software acquisition the contract enforces the parties' rights and obligations on ownership and licensing of intellectual property, maintenance, warranties, arbitration, upgrades, fitness for purpose, security, escrow and access; for acquisition of development resources it covers ownership and licensing of the developed IP, testing, quality assurance and warranties, with legal advice obtained; and for infrastructure, facilities and related services it covers service levels, maintenance, access, security, performance, incident handling and warranties.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.