Assets that are critical to service capability are identified, and their reliability and availability are maximised to support business needs: critical assets are identified using the configuration management system, the SLAs and the definitions of services; the likelihood of each failing or needing replacement is considered regularly; customers and users affected are told what effect maintenance is expected to have; planned downtime is built into the production schedule and maintenance is timed to limit the effect on the business; resilience is kept through regular preventive maintenance, performance monitoring and the provision of alternative or extra assets to reduce failures; a preventive maintenance plan covering every item of hardware weighs cost against benefit, vendor advice, the risk of outage and the availability of qualified staff; maintenance agreements that give third parties access to facilities are formal contracts with controls on access, tools, confidentiality and adherence to policies; remote access services and maintenance user profiles are enabled only when needed; and the performance of critical assets is monitored through incident trends, with repair or replacement where required.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.