Data processors must strengthen risk monitoring; on discovering data-security defects/vulnerabilities, immediately take remedial measures; on a data-security incident, immediately take disposal measures and promptly notify users and report to the relevant authority.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.