Information about a player account is collected as the privacy policy and the local law on privacy permit; data not subject to disclosure under the policy is kept confidential except where law requires release; and procedures on securing and sharing player data, account funds and other sensitive information designate one or more employees with primary responsibility for the procedures, determine the nature, scope, locations and storage devices of the information, set the measures against unauthorised access, and set how a data security breach is handled, including telling the regulatory body.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.