Where appropriate, controllers and processors must implement policies and procedures to monitor and limit access to and activities in the room, workstation or facility where personal data is processed, including guidelines on the proper use of and access to electronic media; design office space and workstations to give privacy to those processing personal data considering the environment and public accessibility; define the duties, responsibilities and schedules of individuals involved so that only those actually performing official duties are in the room or workstation at any time; implement policies and procedures for the transfer, removal, disposal and re-use of electronic media; and establish policies that prevent mechanical destruction of files and equipment, securing rooms and workstations as far as practicable against natural disasters, power disturbances, external access and similar threats.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.