Controllers and processors must implement measures giving security appropriate to the risk, in particular for sensitive data. For automated processing, and where applicable manual filing systems, they must after a risk evaluation implement controls for equipment access, data media, storage, users, data access (only data covered by the authorisation), communication (verifiable destinations of transmissions), input (who entered which data and when), transport, recovery of installed systems after interruption, and reliability and integrity (faults reported, stored data not corrupted by malfunction). The controller must record the measures adopted; the Commissioner issues a guideline with detailed rules on data security, logging, disposal, processing and disclosure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.