Control the documented information the system and the standard require so it is available and usable where and when needed and suitably protected against loss of confidentiality, misuse or loss of integrity. As applicable, manage who receives it, who can reach it, how it is found and used; how it is stored and preserved, legibility included; version and change control; and retention and disposal. Documented information from outside sources that is needed to plan and run the system is identified and controlled.
This control maps to 14 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.