Controller and processor implement technical and organisational measures giving security appropriate to the risk, particularly for special categories, taking account of the Federal Office for Information Security's technical guidelines and recommendations; measures may include pseudonymisation and encryption and should ensure ongoing confidentiality, integrity, availability and resilience and timely restoration after an incident. For automated processing, after a risk evaluation, measures must achieve equipment access control, data media control, storage control, user control, data access control, communication control, input control, transport control, recovery, reliability, integrity, processing control, availability control and separability; state-of-the-art encryption can serve several of these.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.