Measures such as access control, monitoring, validation of users and approved destruction stop people from getting at, changing, hiding or destroying records without permission. What was applied to a record, and when, is kept in its process metadata; depending on risk, security incidents touching records are noted there too; and the wider information security and continuity arrangements are extended to cover records systems.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.