Regulation 13 addresses portable computing devices and removable media used to process or store personal data. Such devices must be authorised, encrypted, inventoried, and protected against loss. Use of personal devices for database access must be approved and controlled. Loss of devices containing personal data must be reported and investigated as a security event.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.