Many incumbent systems do not meet the API standards. We need to detail the process for non-conformance.
Suggestions
[ ] A register of services and their conformance is maintained
[ ] For non-conformant services, include a list of standards that aren't met
[ ] List any compensating controls
[ ] Outline a path to resolution
[ ] Define a grace period of non-conformance. Proposal is for 24 months to accommodate large changes in architecture that may be required to achieve conformance.
Summary
Many incumbent systems do not meet the API standards. We need to detail the process for non-conformance.
Suggestions
Drawbacks
None identified
Which area of the standards does this apply to?