The team's threat assessment decides how urgent a situation is and what first steps to take, gathering what facts it readily can about who, what, where, when and why. It should concentrate on the persons of concern and on readily available information gathered discreetly, drawing on sources such as: the reporters or targets of the conduct; the employee's present and past supervisors or managers; the relevant HR representative; personnel files; computers, communication devices and their applications (email, intranet history, messaging); network files; background checks including court and public records where lawful and appropriate; what is publicly visible online (sites, blogs, social platforms, chat forums, posts); and camera footage and door entry logs.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.