Controllers and processors must protect the security, integrity and confidentiality of personal information against accidental, unauthorised or unlawful loss, misuse, destruction, damage, access or processing, by identifying foreseeable risks, setting and maintaining safeguards, regularly verifying them and updating them for new risks, considering pseudonymisation, encryption, resilience, timely restoration and periodic risk assessment, and having regard to accepted and industry practices, the volume and sensitivity of data, likely harm, extent of processing, retention period and cost relative to size.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.