Per Norwegian PDPA + GDPR Article 32: security of processing. Requirements include (a) implement appropriate technical + organisational security measures appropriate to risk per GDPR Article 32 + (b) implement Encryption of personal data at rest + in transit + appropriate to classification + (c) implement Pseudonymization Techniques where appropriate + (d) implement Access Control for personal data including authentication + authorisation + audit + (e) conduct Regular Security Testing and Assessment + (f) integrate with broader information security programme + (g) align with NSM (Norwegian National Security Authority) guidance + Datatilsynet expectations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.