Guidance: the organization should create and keep up enough documented information for the system operates effectively, is understood by people under its control and relevant interested parties, and its processes are carried out as planned, in a way that reflects its culture and needs. Processes, plans and programmes should be maintained for consistency and repeatability; records should be kept to evidence activities and results. Key activities can be specified through documented processes, or where a process is not documented, affected people should be informed of the requirements through communication or training. A manual is optional and need not follow the clause structure. Unnecessary or complicated documentation diminishes effectiveness; any useful, legible, accessible medium can be used, and documentation can be combined with other management systems. The minimum to maintain: scope, policy, risks and opportunities, planning processes, aspects, impacts, criteria and significant aspects, compliance obligations, objectives, operational control processes and emergency processes; the minimum to retain as records: competence, communications, monitoring results, compliance evaluations, audit programme and results, management review results, and nonconformities and corrective actions.
This control maps to 5 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.