Throughout development, testing, control testing included, is carried out continuously in the right environment as the test plan and development practices require, with business process owners and end users taking part in testing: solutions and components are tested according to the plan by testers who are independent of the team that built them, joined by representative process owners and end users, and results go into a test log; test instructions are clearly defined and strike a sensible balance between scripted automated tests and interactive testing by users; testing covers how business processes and IT components fit together and non-functional needs such as security, privacy, interoperability and performance; errors are found, logged and graded (minor, significant, mission-critical), and testing is repeated until every significant error has been fixed, with an audit trail of the results; and outcomes are recorded and shared with stakeholders as the plan specifies.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.