Maintain the risk assessment per NIST SP 800-30 Rev 1 Section 3.3 Step 8 (Maintaining the Risk Assessment) and integrate with the NIST Risk Management Framework (SP 800-37) and continuous monitoring (SP 800-137). Maintenance must (a) trigger updates on significant change (system change, environment change, threat change, control failure, incident), (b) refresh annually at minimum even without trigger, (c) update the risk register on each control implementation, change, or failure, (d) feed risk assessment outputs into RMF Authorize step (information needed for authorising official ATO decision), (e) align with continuous monitoring strategy (NIST SP 800-137) so monitoring evidence updates assessment inputs automatically where possible. Documentation retention must support audit readiness with chain-of-custody from threat intelligence + vulnerability scan + control test through to risk register entry through to authorisation decision.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.