Guidance: an audit programme should be established, addressing a single management system standard or several, or other requirements, audited separately or together, with an extent based on the auditee's size and nature and on the nature, functionality, complexity, risks and opportunities and maturity of the systems audited, paying particular attention to multiple sites and outsourced functions and scaling down for small organizations. In setting it up, account should be taken of what the auditee is trying to achieve as an organization, its external and internal issues, interested party needs and expectations, and information security and confidentiality requirements. Those managing it should protect the integrity of audits from undue influence, give priority to matters of higher inherent risk and lower performance, and be competent. The programme should record its objectives, its risks and opportunities and actions, the scope of each audit, the schedule, audit types, criteria, methods, criteria for selecting team members and relevant documented information, and should be monitored, measured and reviewed for improvement, following a Plan-Do-Check-Act flow.
This control maps to 16 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 16 it maps to, and the evidence behind each claim, over MCP and REST.