The enterprise continuously monitors, benchmarks and improves its I&T control framework and control environment so that organisational objectives are met: the limits of the internal control system are identified, including how controls extend to outsourced and offshore development or production; the state of external service providers' internal controls is assessed and their compliance with legal, regulatory and contractual obligations confirmed; monitoring and evaluation follow the organisation's governance standards and frameworks and practices accepted in the industry, covering both control performance and the control environment; exceptions in controls are reported promptly, followed up and analysed, corrective actions are prioritised and carried out according to the risk profile, and exceptions that keep recurring are brought to management's attention; independent evaluations by internal audit or by peers are considered; the control system is kept current as business and I&T risk, the control environment and processes keep changing, with gaps assessed and improvements recommended; and the performance of the control framework is evaluated regularly against industry standards and good practice, with a continuous improvement approach considered.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.