Testing ascertains the behaviour or performance of the software against its test specification, as far as the coverage of the tests allows. Each test specification (overall software, integration, software/hardware integration, component, application data) is written before the tests and defines test cases and data, the types of tests, the test environment with tools, configuration and programs, the criteria on which completion is judged and the required coverage; testing not fully documented, or performed by the designer before verification, does not count. Each test report states the outcome and whether the test specification's objectives and criteria were achieved, records failures with their reasons, is in an auditable form, records test cases and results preferably in machine-readable form for later analysis, prefers repeatable automated tests, states the coverage achieved and which items, in which configuration, were tested (6.1.4.1 to 6.1.4.5).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.