The organization makes sure product that fails to meet requirements is identified and controlled so it is not used or delivered by mistake. A documented procedure sets the controls, and the responsibilities and authorities, for identifying, documenting, segregating, evaluating and disposing of nonconforming product. Evaluating a nonconformity includes deciding whether an investigation is needed and whether any outside party responsible for the nonconformity must be told. Records are kept of what each nonconformity was and of the action taken afterwards, covering the evaluation, any investigation and the reasons behind the decisions made.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.