Implement technical and organisational security measures + breach notification process under Article 19 + Reglamento Articles 61-67 + INAI Recommendations on Security Measures 2018 amended 2024. Article 19 requires administrative + technical + physical security measures sufficient to ensure confidentiality + integrity + availability of personal data + appropriate to nature of data + state of art + risk. INAI Security Recommendations baseline includes encryption + access controls + identification and authentication + audit trails + secure development lifecycle + supplier security + business continuity + workforce training. Reglamento Article 63 Breach Notification - controller must notify affected data subjects of any vulnerability that significantly affects rights (NOTE: NO SPECIFIED TIME LIMIT - significant gap vs GDPR 72-hour + 2017 LGPDPPSO public-sector law similarly lacks time limit). Controller must investigate cause + take corrective measures + assess affected data subjects impact + update Security Manual + breach register maintenance. INAI does NOT need to be notified at federal level (private sector) under current LFPDPPP (notification to INAI optional unless serious public concern - unlike Public Sector LGPDPPSO which requires INAI notification). CERT-MX coordination for cyber-component breaches + Comision Nacional de Seguridad + Direccion General de Operaciones Cibernetics (DGOC). Sectoral CONDUSEF (financial) + CFE (energy) + COFEPRIS (health) + IFT (telecom) parallel breach notification requirements may apply.
This control maps to 115 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 115 it maps to, and the evidence behind each claim, over MCP and REST.