A provider of a public electronic communications service must take appropriate technical and organisational measures to safeguard the security of the service, if necessary together with the network provider, which must meet the service provider's reasonable requests for that purpose. At a minimum the measures must ensure personal data is accessed only by authorised personnel for legally authorised purposes, protect stored or transmitted personal data against accidental or unlawful destruction, loss or alteration and unauthorised or unlawful storage, processing, access or disclosure, and put in place a security policy for the processing of personal data. A measure is appropriate when, having regard to the state of technology and the cost of implementation, it is proportionate to the risks it guards against.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.