Where the test changes systems, the organisation ensures the provider keeps a detailed, timed list of actions taken against compromised systems and of every configuration change, restores settings to their original state where possible (clearly flagging any change that could not be reversed), and, on completion, removes anything introduced during the test (test artefacts, any access mechanisms, and any accounts created for the test), so the environment is returned to its prior state and the change list is handed over for the organisation to verify. Critical services are not modified without agreement, and any access mechanism introduced with agreement requires authentication and prior written consent where its removal could cause downtime. Logs are not cleared or modified unless the contract authorises it, and are backed up first if they are.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.