The government information security mechanism must include the measures to apply when processing personal data against any risk, threat, vulnerability, unauthorised access, loss, alteration, destruction or accidental or unlawful communication; it covers all public-sector institutions of Art. 225 of the Constitution and third parties providing public services by concession or other legal forms, which may add further measures.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.