A maintenance plan for solution and infrastructure components is prepared and carried out, and is reviewed from time to time against business needs and operational requirements: it addresses patch management, upgrade strategies, risk, vulnerability assessment and security requirements; before a maintenance activity goes ahead, its importance for the existing design, functionality and business processes is assessed with regard to risk, effect on users and available resources, and business owners understand what it means to classify a change as maintenance; major changes that substantially alter the design, functionality or processes of an existing solution go through the same development process as new systems; and the pattern and amount of maintenance are analysed periodically for unusual trends that point to quality or performance problems, to whether a major upgrade is worth its cost, or to a need for replacement.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.