Per Qatar Law No. 13 of 2016 on Personal Data Privacy Protection: security. Requirements include (a) appropriate technical + organisational measures + (b) encryption + pseudonymisation + (c) access control + (d) regular testing + (e) integrate with broader InfoSec.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.