The governing body monitors how well I&T governance in the enterprise works and performs: whether the governance system and its mechanisms (structures, principles, processes) function effectively and give the oversight that allows I&T to create value. It assesses those to whom governance responsibility has been delegated; periodically checks whether the agreed mechanisms exist and work; assesses how governance is designed and identifies actions that correct deviations; keeps watch over how far I&T satisfies obligations from regulation, legislation, common law and contract as well as internal policies, standards and professional guidelines; oversees whether the enterprise's system of control is effective and complied with; and monitors the routine mechanisms confirming that I&T use meets its obligations.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.