Guidance: the organization should set up a process that judges how far it is meeting its compliance obligations, by monitoring and measuring its performance, then analysing and reviewing it, against the obligations identified under 4.2 and 6.1.3. All obligations should be evaluated periodically, with frequency varying by legal requirement, relevance, changes to obligations, past performance and the potential effects of non-compliance, and expected process variation. Methods include facility inspections, observations and interviews, project reviews, review of sample results against limits, verification sampling and review of legally required records. Internal audits can test the effectiveness of the compliance evaluation process but cannot themselves demonstrate compliance. Where a failure or potential failure is identified the organization should act, using the corrective action process where needed, and communicate or report to the relevant interested parties where appropriate; a non-compliance corrected by the system's processes is not necessarily a system nonconformity. Evaluation should keep knowledge of compliance status current and provide timely input to management review. Documented information should be retained, such as evaluation reports, audit reports and communications.
This control maps to 8 controls across 6 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 8 it maps to, and the evidence behind each claim, over MCP and REST.