Handlers must adopt measures to ensure handling complies with law and to prevent unauthorised access, leakage, tampering or loss: internal management systems and procedures, classified management, technical security (encryption, de-identification), access controls and operational authorisation, training, and an incident response plan.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.