Taking into account the state of the art, costs, the nature, scope, context and purposes of processing and the risks, controller and processor must implement technical and organisational measures ensuring a level of security appropriate to the risk, including as appropriate pseudonymisation and encryption, ongoing confidentiality, integrity, availability and resilience of systems and services, the ability to restore availability and access in a timely manner after an incident, and a process for regularly testing, assessing and evaluating the effectiveness of the measures, with particular regard to the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.