Because sector rules increasingly require appropriate cryptography and regulators are expected to require the new PQC standards and set deprecation dates for older ones, the organisation identifies the regulatory bodies and laws that apply in its region and sector and follows both technical and legislative developments. The handbook points to the ISO/IEC 27000 series (cryptographic policy and risk-based controls), NIS2 (proportionate cryptographic measures reflecting the state of the art), GDPR Article 32, US FISMA and FIPS, the 2022 US memorandum and the OMB strategy, CNSA 2.0 for US national security systems, and sector laws such as DORA, HIPAA and the European Electronic Communications Code, and recommends deploying only standardised algorithms.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.