The organization should decide what the plan covers and what other documents cover, so nothing is duplicated. The scope depends on the processes and quality characteristics peculiar to the case, on requirements from the customer or other interested parties to include processes that are not peculiar to the case but that they need for confidence, and on how far a documented QMS backs the plan up; where procedures do not yet exist, they may have to be written. Going over the scope with the customer, or with other interested parties, can help them use the plan for monitoring and measurement.
This control maps to 14 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.