Regulation 4 requires that changes to systems holding personal data are managed through documented change control. Development environments must be separated from production. Test data should not be real personal data unless protective measures are applied. Significant system changes must be reflected in the definition document and risk assessment.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.