The planning group should sketch a program suited to what the organization can afford, what it needs and how it works, and set realistic deadlines for developing and rolling it out. In design it should take into account what this standard requires and recommends, obligations from law, regulation and contract, and useful material from government agencies, professional and trade bodies and other sources. It can also draw on benchmarking with similar organizations that have implemented programs, advice from outside experts in security, HR, law and psychology with deep knowledge of these topics, and legal review of the aspects that need it.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.