s.10.3: an organization must keep and maintain a record of every breach of security safeguards involving personal information and provide it to the Commissioner on request.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.