Problems (non-compliance with plans or standards, deficient process outputs, anomalous product behaviour, inadequate tools or processes) are recorded and resolved, starting no later than the baseline from which credit is taken. Every problem gets a report identifying the affected configuration; reports needing corrective action invoke change control; closed reports describe the action taken including data changes; not all reports must close before certification, but all are evaluated and those with safety or certification impact are closed; and the system tracks status, approval and disposition.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.