Business process activities and their related controls are assessed and monitored continually according to enterprise risk so that processing controls match what the business needs: the control activities that key processes require to meet control requirements attached to objectives that are strategic, operational, compliance-related or about reporting are identified and documented; controls are prioritised by their inherent business risk and key controls are identified; each key control activity has an owner; automated controls are implemented; control activities are monitored end to end to find opportunities for improvement; and the design and operation of process controls are improved continually.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.