A participant must have adequate arrangements for the confidentiality, integrity and availability of information it holds or uses, including identifying information assets, controls (automated where possible) against unauthorised access, monitoring for unauthorised access or use, protection from theft, loss or corruption, availability arrangements, and records of unauthorised access to critical services or sensitive information kept for seven years.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.