Documented policies and procedures protect patrons' personally identifiable information, naming the responsible employee, and cover: management officials responsible for design, implementation and evaluation; how the nature, scope and storage locations and media of PII are determined; preventing access to a patron's PIN or password; ensuring only the patron changes it; protecting PII from employees, business partners and outsiders; notifying patrons of privacy policies; the response to a data security breach, including notification to the Board's Enforcement Division; and compliance with local, state and federal privacy and security laws.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.