The organization should define, describe and allocate who is responsible and has authority, and who is accountable, for the configuration management process, taking into account how complex the product or service is and what kind it is, what each life cycle stage needs, where the activities directly involved in the process meet, which other interested parties inside or outside the organization are or should be involved, who has authority to verify implementation activities, and who the dispositioning authority is.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.