Controllers (and their representatives) must protect personal data against negligent loss and unauthorised destruction, alteration, access or processing with safeguards reflecting the state of technology, cost, the nature of the data and the risks to subjects; the regulations list information security policies, risk assessment, resilient processing, need-to-know access, secure transfer and storage, backups and logs, audit trails and monitoring, separate protection for sensitive data, breach detection and handling procedures, and regular software vulnerability testing.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.