Monitoring every online activity with inspection tools such as TLS interception, next-generation firewalls or unified threat management is disproportionate and intrudes on the confidentiality of communications, so less invasive means should be explored first. Where some interception is strictly necessary, the tool should be set up to avoid permanent logging, for instance by blocking suspicious traffic and sending the user on to a portal where they can ask for a review, and if general logging is strictly needed, by storing logs only when an incident is flagged and keeping as little as possible.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.