Per RA 10173 + IRR + NPC Security Circulars: security of processing. Requirements include (a) implement Security of Personal Data including organisational + physical + technical security measures appropriate to risk per IRR + NPC guidance + (b) maintain Access and Activity Logging per IRR Section 38 + (c) implement encryption at rest + in transit appropriate to classification + (d) conduct regular security testing + assessment + (e) integrate with broader information security programme aligned to NPC guidance + (f) maintain documented security baseline + improvement.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.