Guidance: while the audit is running, information that bears on its objectives, scope and criteria, including where functions, activities and processes meet, should be gathered through suitable sampling and verified as far as practicable. Information can be accepted as audit evidence only if it has been verified to some extent, with professional judgement on the reliance placed on weakly verified information; evidence leading to findings should be recorded; and new or changed circumstances, risks or opportunities discovered should be addressed. Methods of collection include interviews, observations and review of documented information, following the typical process from sources of information through collection, verification, evaluation against criteria, findings and conclusions.
This control maps to 12 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.