Dominican Republic Law 172-13 Articles 21-25 + 33-35 Security Measures and Incident Handling. Article 25 Security Measures (Medidas de Seguridad) - appropriate technical + organisational measures proportionate to risk + nature of data + state-of-the-art + including: (1) Encryption at rest and in transit for sensitive and credit information data + AES-256 minimum + TLS 1.3 + key management; (2) Pseudonymisation and anonymisation techniques where applicable; (3) Access control (RBAC + least privilege + segregation of duties + privileged access management) + identity and authentication management; (4) Logging + monitoring + audit trails + minimum 5-year retention for credit information records + 1-year general; (5) Vulnerability management + patching + penetration testing + secure SDLC; (6) Physical security + data centre Tier III + biometric access + CCTV + visitor management; (7) Backup + business continuity + disaster recovery + tested restore procedures. Article 22 Breach Notification (Notificacion de Brechas) - obligation to notify Superintendencia de Bancos for credit information bureaus + data subjects + without undue delay (interpreted as 72 hours per recent SB Circulars) + earlier where high-risk + content (nature + categories + approximate number + consequences + countermeasures + contact). Article 33 Incident Response Procedures - documented IRP + CSIRT + tabletop exercises + coordination with Centro Nacional de Ciberseguridad (CNCS) + Ministry of Public Administration + Departmento de Investigacion de Crimenes y Delitos de Alta Tecnologia (DICAT) + International CERT cooperation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.