An agency's cloud adoption plan should address: (1) the outcomes and benefits cloud adoption will deliver; (2) risks that cloud use introduces or reduces, and the agency's risk tolerance; (3) financial and cost accounting models; (4) shared responsibility models; (5) cloud deployment models; (6) the cloud security strategy; (7) resilience and recovery approaches; (8) recovering data when a contract ends; (9) the strategy for exiting the cloud, plus other contractual arrangements; and (10) a high level outline of the enabling foundation services for cloud use, namely identity for users, devices and systems; key management and encryption; management of information; alerting and logging; incident management; management of privileged activities; and cost management.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.