The governing body should identify the relevant internal and external stakeholders in the organization's IT, consult them and involve them appropriately; in particular it should make sure that obligations around the use of IT and data are clearly defined, and that any breach of them is communicated at once so that the organization and the stakeholders concerned can deal with the consequences. This is the task the third edition adds to the model.
This control maps to 14 controls across 5 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.