The controller must take security, technical and organisational measures that protect the data against any breach of security and integrity or any unauthorised disclosure, alteration, addition, destruction or act, in accordance with the instructions the Council issues for the purpose (the Council published Instructions for Security, Technical and Organisational Measures, not held here).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.