Content monitoring is hard to justify where network traffic data would meet the purpose; the employer must notify workers in advance (in policy documents) if content may be monitored in exceptional circumstances and must not access content without a clear policy stating when that can happen. Before monitoring it should consider narrowing checks using network data (emails to rival firms, for instance), the duty of confidence to workers and customers, excluding lines such as union representatives, that even a ban on personal use does not justify reading personal messages (investigate breaches through network data first), letting workers mark messages personal, and the reliability of the records.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.