Establish + implement + maintain reasonable administrative + technical + physical data security practices to protect the confidentiality + integrity + accessibility of personal data appropriate to the volume + nature of the personal data. Align with NIST Cybersecurity Framework or equivalent. Comply with New Jersey breach notification law (N.J.S.A. 56:8-163.4) requiring notification to NJ State Police + AG + affected residents in most expeditious time possible (typically 30 days). Maintain incident response plan covering preparation + detection + containment + eradication + recovery + lessons learned + breach reporting.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.