Move a defined set of system functions or resources between locations at a defined frequency, so that what an adversary located yesterday is not where it sits today. Virtualization, distributed processing and replication make it practical to relocate the components carrying critical missions and business functions, and changing addresses, naming or network topology achieves the same targeting uncertainty. Fragmentation is a second route to the same end: partitioning a data set across several components means compromising any one of them yields only a portion of the whole, and the adversary must find them all. Organizations weigh this against the burden it places on their own defenders, and update management and security tooling and train staff accordingly.
This control maps to 5 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
NIST SP 800-172 3.13.5e is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-172 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 24 of 35 NIST SP 800-172 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 5 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.