Schedule 1, Seventh Principle: appropriate technical and organisational measures must be taken against unauthorised or unlawful processing and against accidental loss, destruction of, or damage to personal data; processors must provide sufficient guarantees.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.