The enterprise continuously watches for changes in local and international law, regulation and other external requirements and identifies, from an I&T perspective, what it is mandated to comply with: responsibility is assigned for identifying and tracking changes in legal, regulatory and other contractual requirements that bear on how IT resources are used and how information is processed; every potential requirement is identified and assessed for its effect on I&T activities in fields such as privacy, data flow, financial reporting, internal controls, intellectual property, industry regulation and health and safety; the effect of legal and regulatory requirements relating to I&T on contracts with providers and trading partners is assessed; the consequences of failing to comply are defined; independent counsel is sought where appropriate on changes to laws, regulations and standards; a current log records every relevant requirement with its effect and the action it calls for; and the enterprise keeps one harmonised, integrated register of its external compliance requirements.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.