Implement technical and organisational security measures + breach notification process aligned with GDPR Articles 32-34 + Montenegro National Cyber Security Strategy + CIRT-MNE. Security measures appropriate to risk including encryption + access controls + activity logging + secure development + supplier security + business continuity + workforce training. AZLP Security Guidelines providing baseline. Breach notification within 72 hours to AZLP + concurrent affected data subject notification without undue delay where high risk + breach register maintenance + breach response plan + post-incident review. Coordination with CIRT-MNE (Computer Incident Response Team Montenegro) under Ministry of Public Administration Digital Society and Media + Cybercrime Convention (Budapest Convention) signatory + Council of Europe Convention 108+ + national Cyber Security Strategy 2018-2021 + 2022-2026 (in development) + Cybersecurity Act 2018 + NIS2 Directive transposition expected. Critical Infrastructure (banking + telecommunications + energy + transport + healthcare) face dual notification (AZLP + CIRT-MNE). Central Bank of Montenegro Cybersecurity Guidelines for financial sector + EKIP electronic communications cyber requirements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.