Controllers and processors must implement all appropriate and necessary state-of-the-art organisational, technical and other security measures to protect personal data against any risk, threat or vulnerability, having regard to the nature of the data, the scope and the context (detailed in Arts. 37 to 41).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.