Protection. Section 22 requires organisations to protect personal data by making reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.