Per RA 10173 + NPC Circular 16-03: breach notification. Requirements include (a) maintain Breach Management Team and Procedures per NPC Circular 16-03 + (b) implement Personal Data Breach Notification to NPC within 72 hours of knowledge of breach involving sensitive personal information or threatening to cause harm + notify affected data subjects per NPC requirements + (c) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (d) maintain breach log + breach management team + tabletop exercises + (e) integrate with broader incident management + (f) maintain documentation supporting NPC reporting.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.