Top management is required to set and communicate a PAP policy, and the policy is required to: commit to avoiding and preventing disruptive events and to making them less likely and less harmful, with an explicit commitment to keeping people and the community safe; fit with the organization's other policies; provide the structure within which PAP objectives, targets and programmes are set and revisited; spell out what the organization requires of its PAP programme, the range of physical security applications covered and how they are implemented, reviewed and replaced; commit to meeting applicable legal and other requirements the organization signs up to; be documented, put into effect, evaluated and kept current; reach every person who needs it among staff and those acting for the organization; be available to appropriate stakeholders; carry visible top management endorsement; commit to continual improvement; and be reviewed at planned intervals and whenever the operating environment changes significantly.
This control maps to 3 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.