The governing body keeps identifying and engaging the enterprise's stakeholders, records what it understands their requirements to be, and evaluates how governance of enterprise I&T is designed now and should be designed in future. It analyses the internal and external factors that shape that design (obligations from law, regulation and contract, and business trends); determines how much I&T matters to the business; works out how external obligations play out within the governance system; takes account of the broader control environment of the enterprise; brings the ethical use of information, and its effects on society, the environment and stakeholders, into line with the enterprise's direction; and on that basis sets out guiding principles, the model for making I&T decisions, and the levels of delegated authority, with threshold rules for decisions about I&T.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.