Controllers and processors must implement technical and organisational measures giving a level of security appropriate to the risk, having regard to the state of technology, cost, the nature, scope, context and purposes and the likelihood and severity of risk, including as appropriate pseudonymisation and encryption; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of systems and services; the ability to restore availability of and access to data in reasonable time after a physical or technical incident; and a process for regularly testing, reviewing and evaluating the effectiveness of the measures. The assessment must weigh in particular the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Adherence to a code or certification may evidence compliance. Anyone acting under the controller's or processor's authority with access to data may process them only on the controller's instructions unless law requires otherwise.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.