Performance is reviewed against targets periodically and reported through a method that gives a brief, rounded picture of how I&T is performing and suits the enterprise's monitoring system: reports are short, easy to understand and fitted to management's needs and the audience so decisions can be taken in time (for example scorecards or traffic-light reports); they go to the relevant stakeholders; causes of deviations are analysed, remedial actions started, responsibilities assigned and followed up, and all deviations are reviewed periodically for root causes; performance and compliance are built into individual performance objectives and tied to reward where feasible; values are compared with internal targets and benchmarks and, where it can be done, with external benchmarks from the industry and competitors; trends are analysed and acted upon; and changes to goals and metrics are recommended where appropriate.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.