Section 17 requires the database owner, holder, and manager to ensure that the database has appropriate security. Each database must have a designated database manager (responsible for compliance) and a database holder where the data is held by a third party. Larger databases must appoint a security officer. The Data Security Regulations 2017 operationalise this duty in detail.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.