Agencies should review the components listed in the table in this control, and should also make sure that adjustments and changes arising from vulnerability analysis stay consistent with the agency's vulnerability disclosure policy. The table covers: information security documentation (the SecPol, the Systems Architecture, SRMPs, SSPs, the SitePlan, SOPs, the VDP and IRP, and assurance reports from any third party); dispensations (reviewed before the expiry date that has been identified); operating environment (when a threat that has been identified appears or changes, the agency gains or loses a function, or functions are relocated to a different physical environment); procedures (following a test exercise or an information security incident); system security (on a regular basis, items that could affect the system's security); threats (changes in the threat environment and risk profile); and the NZISM (changes to baseline or other controls, and any new controls and guidance).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.