Taking into account the nature, scope, context and purposes of processing and the risks of varying likelihood and severity to data subjects, the controller implements appropriate technical and organisational measures to ensure and be able to demonstrate compliance with the Law and its regulations, reviewed and updated when necessary; the regulations will specify the measures, their review and protection by design and by default.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.