All personnel with software responsibilities are competent to carry them out, demonstrating the ability to perform the tasks involved correctly, efficiently and consistently, to high quality and in changing conditions. Training, experience and qualifications of everyone involved in every lifecycle phase including management are appropriate, justified for the application at hand (recommended at every level, required above Basic Integrity in 2001), and written into the software quality assurance plan with evidence of competency in the engineering of the application area, software engineering, computer systems engineering, safety engineering and the legal and regulatory framework; how people are assigned to roles is described and gaps in key competencies are closed by training that is itself recorded (5.2.2.1 to 5.2.2.4).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.