Solution components are built up progressively in a separate environment from the detailed designs, in line with the standards and requirements that apply to development, documentation, quality assurance and approval: processes, supporting services, applications, infrastructure and data stores are developed from the detailed design in an environment kept apart from others; where third-party providers take part, their contracts deal with maintenance, support, development standards and licensing; change requests, together with reviews of design, performance and quality, are tracked with affected stakeholders actively involved; every component is documented to defined standards, with components and their documentation under version control; for acquired solutions, the effect of customising and configuring them on their performance and efficiency, and on how well they interoperate with the operating systems, applications and other software already in place, is assessed; and those who build and integrate infrastructure components that are highly secured or access-restricted have clearly defined responsibilities for using them and understand those responsibilities.
This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.