The organization keeps procedures to identify legal and regulatory obligations, plus other commitments it has signed up to, that relate to the hazards, threats and risks of its facilities, activities, functions, goods, services, supply chain, environment and stakeholders, and to determine how they apply to those risks and their impacts and whether they are met. It documents and updates this information and makes sure applicable requirements are taken into account in building, running and maintaining the resilience system. Annex B lists sources: national and international law, state or regional law, local rules, and other commitments such as agreements with authorities or customers, non-regulatory guidelines, voluntary codes, labelling or product stewardship commitments, trade association rules, agreements with community groups, public commitments and corporate requirements.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.