The organization audits its resilience policy internally at planned intervals and when management decides, to find out whether management objectives, controls, processes and procedures conform to this standard and applicable legal requirements, to its risk management requirements, are effectively implemented and maintained, and perform as expected. The audit programme reflects the status and importance of the areas audited and earlier results; criteria, scope, frequency and methods are set; auditors are chosen and audits run so the process is objective and impartial, and nobody audits their own work. A documented procedure says who plans and runs audits and how, and how results are reported and records kept (see A.6.5). Management of the audited area makes sure actions to remove nonconformities and their causes are taken without undue delay, and follow-up verifies the actions and reports the result. Annex B adds that auditors may be internal or external, must be competent and impartial, and that combined audits with security, safety or environmental audits need a clearly defined purpose and scope for each.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.