Acceptable usage of cloud resources. Level 1 (a to c): rules for acceptable use approved by authorised parties, including the authentication technology, services, devices and approved products that may be used; conditions for network and messaging use; and documented, communicated usage rules. Level 2 adds (a) handling and labelling rules for information by network location and (b) rules for information handling over network technologies such as remote and wireless access (the latter with no ISO/IEC 27001 counterpart); Level 3 is the same.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.