The operator must establish, implement, and maintain reasonable procedures to protect the confidentiality, security, and integrity of personal information collected from children. The 2025 amendments require a written information security program with safeguards appropriate to the sensitivity of the data and the operator's size and complexity, designation of an employee to coordinate it, periodic risk assessment, and obtaining written assurances from third parties to whom children's data is released that they will maintain its confidentiality, security, and integrity.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.