A controller must establish, implement and maintain reasonable administrative, technical and physical data security practices appropriate to the volume and nature of the personal data, to protect confidentiality, integrity and accessibility.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.