Objective ISO/IEC 27002 12.4 applies. Control, in substance: the customer is to be able to observe defined aspects of how the cloud services it uses are operating. Cloud service customer: request information from the provider on the service monitoring capabilities available for each cloud service. Cloud service provider: provide capabilities that let the customer monitor specified aspects of the service's operation relevant to the customer, for example whether the service is being used as a platform to attack others or whether sensitive data is leaking from it; protect use of the monitoring capabilities with access controls so that they give access only to information about the customer's own service instances; document the capabilities for the customer; and provide monitoring data consistent with the event logs of 12.4.1 that assists with SLA terms.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.