Under GDPR art. 32, providers adopt, also through the parties entrusted with the service, technical and organisational measures appropriate to the risk; those operating on networks ensure personal data are accessible only to authorised personnel for lawfully authorised purposes; the measures protect traffic, location and other stored or transmitted data against accidental or unlawful destruction, loss, alteration, storage, processing, access or disclosure and ensure a security policy is implemented; where network measures are needed the service provider adopts them jointly with the network provider, disputes going to AGCOM. Breach is sanctioned under art. 166(1).
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.