For each kind of product or service being designed and developed, the organization identifies the requirements that are essential, taking into account: functional and performance requirements; what was learned from earlier, comparable design work; the laws and regulations that apply; the standards or codes of practice it has committed to implement; and what could go wrong, given the nature of the product or service, if it failed. The inputs must be adequate for design, complete and free of ambiguity; any inputs that conflict are resolved, and documented information on the inputs is retained.
This control maps to 12 controls across 9 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.