An employer uses a data surveillance device to conduct surveillance of a worker only in line with an employer policy on data surveillance of workers, notified to the worker before the surveillance so that the worker can reasonably be assumed to know and understand it. The policy states how the employer's computer resources (including internet access and electronic communication applications) may and must not be used, which usage information is recorded in logs and who can see those logs, and the way the employer checks and audits compliance with the policy. Failure is an offence (s 18(3), 20 penalty units).
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.