Assurance is obtained and reported that policies, principles, standards, procedures and methodologies are complied with and adhered to, and corrective actions on compliance gaps are confirmed as closed promptly: business and IT process owners and heads of units confirm at regular intervals that internal policies are complied with; compliance levels are assessed through periodic internal and external reviews, independent where appropriate; where required, third-party I&T providers give assertions that they comply with applicable law, and business partners give assertions on compliance for electronic transactions between companies; reporting against legal, regulatory and contractual requirements is integrated across every business unit of the enterprise; and non-compliance is monitored and reported, with its root causes investigated where needed.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.