There are two routes by which a vendor can remediate, usually one and occasionally both. For a vulnerability in a service, it follows its own processes for deploying updates or changing configuration on production systems. For a vulnerability in a product, once it is confident the remediation works, it releases it through the processes ISO/IEC 29147 sets out. Where users must also do something (change passwords, sign out and back in), the vendor tells them in a security advisory under ISO/IEC 29147, and where an outside party made the report, ISO/IEC 29147 governs how the vendor deals with external interested parties.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.