Emergency changes are handled carefully so that they cause no further incidents; they are controlled, carried out securely, and assessed and authorised properly once made: the organisation defines what counts as an emergency change; a documented procedure covers declaring, assessing, giving preliminary approval to, authorising after the event and recording such changes; every arrangement for emergency access used to make a change is properly authorised, documented and withdrawn once the change is in place; and all emergency changes are monitored, with reviews after implementation that involve every party concerned, look at root causes such as problems in business processes, application development, infrastructure, testing or the environment, and start corrective action.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.