When imaging or copying the system is possible, it may be appropriate or necessary to examine it in operation by interacting with it or watching it run. Investigators reproduce the original environment as faithfully as they can, in hardware or software, using verified virtual machines (ISO/IEC 27041), copies of the original hardware or the original itself; any emulation is as close to the original as possible, and changes needed to run the copy in an emulator must not materially alter the system's behaviour or the evidence. Some malware detects virtual environments and behaves differently or refuses to run, so emulation needs extra care there.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.