Business process activities and their related controls are operated according to enterprise risk so that processing of information is complete, valid, timely, accurate and secure and reflects legitimate, authorised business use: whoever originates a transaction is authenticated and their authority checked; origination and approval are performed by different people; transactions are checked for accuracy, completeness and validity through controls including sequence, range, limit, reasonableness, validity, existence, table look-up, check digit, key verification, completeness and duplicate checks, logical relationship checks, and time edits, with the validation rules and criteria reviewed periodically; incorrectly entered data are corrected and resubmitted without weakening the original authorisation levels, and original source documents are retained so transactions can be reconstructed; data integrity and validity are kept throughout the processing cycle so that erroneous transactions do not disrupt valid ones; output is handled in an authorised way, reaches the correct recipient, is protected while transmitted and is checked for accuracy and completeness; data integrity is preserved through unexpected interruptions and confirmed after failures; and transaction data moving between applications and functions, within or beyond the enterprise, are checked for correct addressing, genuine origin and intact content, with authentication and integrity protection applied in transit.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.