The program should include a general protocol, agreed beforehand, by which the Threat Management Team assesses, investigates, manages and resolves reports under the policy. It may cover: who receives reports and to whom they escalate; who does the first information gathering; when a report goes exclusively to the team rather than to HR or employee relations under ordinary protocols; the first actions the team will consider on receipt; how reports are coordinated with related channels such as an anonymous ethics or tip line; when further investigation happens, what steps may be taken and which specially trained investigators do it; the triggers and thresholds for bringing in outside help such as lawyers and threat assessment specialists; when outside law enforcement is engaged; the intervention and mitigation approaches the team will generally consider; how the team documents a report or incident and its outcome; how lessons are drawn after an incident on what worked and what to improve; and how the team keeps monitoring, evaluating and improving its intervention and mitigation strategies. Organizations should refine the process in training exercises and over time through daily case work. Clause 8 outlines the process.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.