Regulation 3 requires appointment of an information security officer where the database owner has five or more databases requiring registration, or where the owner is a public body, a bank, an insurer, or holds a large or high-tier database. The officer must have appropriate knowledge and resources, report to senior management, and not have conflicting operational duties.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.