The organization should make sure that anyone whose job means they could cause, prevent, mitigate, respond to or suffer from significant threats and risks is competent through education, training and experience suited to their role, and keep evidence of that competence. It should identify PAP-related competence and training needs, including those arising from interdependencies between business functions, meet them by training or other action and keep the records. It should maintain controls so that everyone working on its behalf is aware of: the PAP policy; how they contribute to the PAPMS and the gains from better PAP performance; the significant threats and risks in their work and the gains from better personal performance; the procedures that reduce the likelihood or consequence of disruption; how to report and refer matters to others for action; why conformity with the policy, procedures and PAPMS matters; their roles, accountabilities and responsibilities for conformity; what happens when they diverge from PAPMS requirements; and the possible consequences of departing from set procedures.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.