Agencies must better manage their use of open source software, so that the Government keeps its innovation and cost benefits while contributing to the security of the open source ecosystem; CISA and OMB, consulting GSA and other agencies, issue joint recommendations on security assessments and patching of open source software and on best practices for contributing to open source projects, which agencies apply. EO 14306 struck the subsection's first sentence (the statement of open source software's role) and left the duty and the recommendations in place.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.