Recorded material should be stored to preserve confidentiality, integrity and availability, with access restricted to authorised people, encryption where possible (other measures where not), secure cloud storage with any international transfer addressed, and an audit trail where footage may become evidence. Live monitors should be visible only to operators and authorised people (hotel reception screens showing corridors positioned away from guests), and recordings viewed in a restricted area. Checks should cover restricted copying, network controls, secure delivery of disclosures, secure control and storage rooms, trained staff with sanctions for misuse and awareness that misuse can be an offence, and applying manufacturers' security updates.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.