Except as the Commission's guidelines allow, no government employee may access sensitive personal information on government property or through online facilities without a security clearance from the head of the source agency; sensitive personal information may not be transported or accessed from a location off government property unless a request is submitted to and approved by the head of the agency, who must approve or disapprove within two business days (silence is disapproval), must limit approved access to not more than one thousand records at a time, and must ensure that any technology used to store, transport or access the information off-site is secured with the most secure encryption standard recognised by the Commission.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.