The controller must further ensure that third parties processing personal information on its behalf implement the security measures required by section 20; the IRR (section 26(f)) requires this to be done through appropriate contractual agreements and to engage only processors that provide sufficient guarantees of appropriate security measures and protection of data subjects' rights.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.