The report includes a technical section for those who will confirm and resolve the findings: an introduction inventorying the people, contacts, assets, objectives, scope, strength of test, approach and grading structure; the intelligence, vulnerability, exploitation and post-exploitation results with the evidence, the level of access achieved and the demonstrated business impact; the effectiveness of the organisation's countermeasures and any incident-response activity triggered; the risk or exposure analysis combining impact with the agreed risk values; and per-finding remediation with mitigating or compensating options. This leaf governs that findings are evidenced, their impact shown and their remediation set out.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.