16 CFR 314.4(d-g). (d) SERVICE PROVIDER OVERSIGHT: (1) take reasonable steps to SELECT + RETAIN SERVICE PROVIDERS capable of maintaining safeguards for customer information; (2) require service providers by CONTRACT to implement + maintain such safeguards; (3) periodically ASSESS service providers based on the risk they present + the continued adequacy of their safeguards. (e) TESTING + MONITORING: (1) IMPLEMENT POLICIES + PROCEDURES to monitor effectiveness of safeguards on an ongoing basis; (2) TEST + monitor at intervals appropriate to the risks. (f) PERSONNEL TRAINING: (1) provide INFORMATION SECURITY TRAINING to personnel + based on risk-relevant roles + responsibilities; (2) verify that key personnel take steps to maintain CURRENT KNOWLEDGE of changing threats + countermeasures; (3) verify that information security personnel have qualifications + skills equal to the importance of their function. (g) PROGRAM EVALUATION AND ADJUSTMENT: EVALUATE + ADJUST the information security program in light of (i) testing + monitoring; (ii) any material changes to operations or services + business arrangements; (iii) results of risk assessments; (iv) any other circumstances that may have material impact.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.