Generic software that is configured by application data or algorithms complies with clause 7 with additional requirements: the types or classes of function configurable by data or algorithms in each system and subsystem are identified in the generic software's requirements specification (8.4.8.2); the interfaces between generic software and data or algorithms are specified during design (8.4.8.3); a rigid separation is enforced so that either can be recompiled and updated without the other unless the defined interface changed, and application specific data are separated from application generic data (8.4.8.4); change control ensures an amendment to the generic software is installed only after it is shown compatible with the existing data or the data revised (8.4.8.5); verification and validation of the generic software make sure every relevant combination of data and algorithms is covered (8.4.8.6); the generic software is designed to detect corrupted data or algorithms where feasible (8.4.8.7); and the application conditions for the generic software and the application tools are written, referencing the user manuals and any constraints on the data or algorithms such as imposed architecture or coding rules (8.4.8.8).
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.