Detection of a dangerous fault (by diagnostics, proof test or other means) in a subsystem with fault tolerance above zero leads to a specified action to reach or hold a safe state, or isolation of the faulty part so the EUC can keep running safely during repair; if repair exceeds the MRT assumed in the random failure calculation, the safe-state action follows. In a zero fault tolerance subsystem used only by low demand functions, detection leads to the safe-state action or repair within the assumed MRT, with additional measures and constraints, documented in the operation and maintenance procedures, giving at least equal integrity meanwhile. In a zero fault tolerance subsystem serving any high demand or continuous function, detection leads to the specified safe-state action.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.