All sensitive personal information maintained by the government, its agencies and instrumentalities must be secured, as far as practicable, with the most appropriate standard recognised by the information and communications technology industry and recommended by the Commission; the head of each agency or instrumentality is responsible for complying with those security requirements while the Commission monitors compliance and may recommend action to satisfy the minimum standards. NPC Circular 16-01 sets the security standards for government agencies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.