The organisation and provider agree how sensitive data encountered during the test is handled: certain data (for example regulated personal or health information) should not be viewed or downloaded, and access is instead evidenced without taking the data (for example proof of access such as file permissions or record counts rather than the content), with care that identifiers are not exposed in the evidence itself. Where regulated data is involved, the systems and their locations used for any collection are agreed so that no applicable law is broken, and the acceptable-use position that lets the testers use discovered data as leverage is confirmed against the organisation's own policies.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.