s.10.1(1): an organization must report to the Privacy Commissioner any breach of security safeguards involving personal information where it is reasonable to believe the breach creates a real risk of significant harm.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.