The team should consider actions aimed at the person behind the concern, whether an employee or other insider or an outside party, including: deeper investigation, possibly searching work computers or networks, public registers, databases, social platforms and other sources it may lawfully use, and above all interviews with colleagues, for expressed hostility, violent thinking and any record of harassment, aggression or violence; bringing in a suitably qualified threat assessment specialist from inside or outside to assess violence risk and advise on addressing the behavior, including specific defusing and treatment measures if needed; for employees, safely handled employment actions such as discipline, suspension or dismissal, or referral to the EAP, transfer, administrative leave and similar steps; where the person shows behavior possibly linked to behavioral or mental health problems, consulting legal counsel on the employer's legal and regulatory duties; for contractors or other connected third parties, taking legal advice and talking to whoever employs the person; where the person's information and activities are harder to reach, further investigation; and appropriate police or legal action.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.