Where appropriate, controllers and processors must adopt a security policy for the processing of personal data; safeguards protecting the computer network against accidental, unlawful or unauthorized usage, interference affecting data integrity or availability, and unauthorized access through an electronic network; the ability to ensure and maintain the confidentiality, integrity, availability and resilience of processing systems and services; regular monitoring for security breaches and a process for identifying and assessing reasonably foreseeable vulnerabilities and taking preventive, corrective and mitigating action; the ability to restore availability and access to personal data in a timely manner after a physical or technical incident; a process for regularly testing, assessing and evaluating the effectiveness of security measures; and encryption of personal data during storage and while in transit, an authentication process, and other technical measures that control and limit access. The Commission monitors the appropriate level of security and may update the measures by issuance (section 29).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.