The resilience documentation includes the policy, objectives and targets; a description of the scope; a description of the main elements and how they are built into the relevant documents; the documents and records this standard requires; and those the organization finds necessary to plan and control processes linked to significant risks. The organization judges how sensitive the information is and protects it from unauthorised access. Annex B says the level of detail depends on size, complexity and staff competence, and that a procedure is documented where failure would harm people, assets or the environment, where compliance must be shown, or where consistency matters.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.