Documented information required by the CMS and this document shall be controlled so it is available and suitable for use where and when needed and adequately protected (from loss of confidentiality, improper use or loss of integrity), through the applicable activities of distribution, access, retrieval and use; storage and preservation including legibility; control of changes such as version control; and retention and disposition. Documented information of external origin that the organization determines necessary for planning and operating the CMS shall be identified as appropriate and controlled; access can mean permission to view only or to view and change.
This control maps to 14 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.