Article 4(1) requires the provider of a publicly available electronic communications service to take appropriate technical and organisational measures to safeguard the security of its services, in conjunction with the network provider where necessary, with the level of security appropriate to the risk. Article 4(1a) requires that those measures include at least: ensuring access to personal data only by authorised personnel for legally authorised purposes; protection against accidental or unlawful destruction, accidental loss or alteration, unauthorised storage, processing or access or disclosure; and a security policy. Article 4(2) requires the provider to inform subscribers of any particular risk of a breach of the security of the network. Article 4(3) requires the provider to notify the competent national authority of a personal data breach without undue delay, and to notify the subscriber/individual where the breach is likely to adversely affect their personal data or privacy; the notification is the historical model behind GDPR Articles 33-34.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.