The device includes a secure way of updating, meaning it is adequately protected against abuse by an attacker (for example genuine update servers, channels protected for integrity, checks that updates are authentic and intact, and protection against rollback). The sole exception is where the use case imposes a resource limit, for example very low bandwidth or energy; cost on its own does not qualify. Status in Table B.1: M C (15) (mandatory, a shall provision; conditional on no resource limit arising from the use case ruling out an update mechanism).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.