Objective ISO/IEC 27002 8.1 applies. Control, in substance: when the cloud service agreement ends, whatever customer assets sit at the provider are to be taken off the provider's systems promptly and handed back where that is needed. Cloud service customer: request a documented description of the termination of service process covering return and removal of its assets and deletion of all copies from the provider's systems, listing all assets and documenting the timetable for termination, which should occur in a timely manner. Cloud service provider: provide information about the arrangements for returning and removing any customer assets on termination of the agreement, documented in the agreement, performed in a timely manner and specifying the assets to be returned and removed.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.