The controller must implement reasonable and appropriate organizational, physical and technical measures to protect personal information against accidental or unlawful destruction, alteration and disclosure and any other unlawful processing, and against natural dangers such as accidental loss or destruction and human dangers such as unlawful access, fraudulent misuse, unlawful destruction, alteration and contamination. The appropriate level of security is determined by the nature of the information, the risks of the processing, the size of the organisation and complexity of its operations, current data privacy best practices and the cost of implementation, and, subject to the Commission's guidelines, the measures must at least include safeguards protecting the computer network against accidental, unlawful or unauthorized use or interference with its functioning or availability; a security policy for the processing of personal information; a process for identifying and assessing reasonably foreseeable vulnerabilities in the network and for preventive, corrective and mitigating action against incidents that can lead to a breach; and regular monitoring for security breaches with the same action process. The IRR details the organizational (section 26), physical (27) and technical (28) measures, modelled as their own leaves.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.