Reasonable personal use of IT tools is tolerated if it does not affect network security or productivity; the employer sets the limits of that tolerance and informs staff. Control of internet (site filtering, virus detection) and email (frequency and size measurement, spam filters) aims to secure the networks and limit abusive personal use. Emails and sites visited are presumed professional and may be consulted by the employer, even when the employee is absent.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.