Controllers and processors must implement appropriate technical and organisational measures to ensure security appropriate to the risk, including pseudonymisation, encryption, confidentiality, integrity, availability, and resilience.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.