The controller notifies the Commission of a notifiable breach by submitting a written or electronic report containing the required contents of notification and the name and contact details of a designated representative. All security incidents and personal data breaches, including those not requiring notification, must be documented in written reports: for personal data breaches, the facts of the incident, its effects and the remedial actions taken; for other security incidents not involving personal data, aggregated data suffices. The reports must be available to the Commission on request and a general summary must be submitted to the Commission annually (IRR section 46(c); NPC Circular 16-03 sets the procedure).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.