The configuration repository is reviewed from time to time, and its completeness and correctness are checked against the intended target: live configuration items are checked against the repository, using discovery tools where needed to compare the physical and logical configuration; every deviation is reported and reviewed so that approved corrections are made or unauthorised assets removed; physical CIs recorded in the repository are checked periodically to confirm they exist, with any deviation reported to management; a target for repository completeness is set and reviewed according to business need; and actual completeness and accuracy are compared with the targets from time to time, with remedial action to improve data quality.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.