For privacy safeguard 12, the steps an accredited data recipient must take to protect CDR data are those in Schedule 2: define and implement security governance, define the boundaries of the CDR data environment, have and maintain an information security capability meeting the minimum controls, implement a formal controls assessment program, and manage and report security incidents. A failure by a direct or indirect OSP to take them for service data is the OSP chain principal's failure, and a failure by a CDR representative or its OSPs is the CDR representative principal's. The steps and controls themselves are carried in 'Australia Consumer Data Right - Banking (CDR)' (AUCDR-IS-STEP1 to STEP5 and AUCDR-IS-1 to 6).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.