A controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices designed to protect the confidentiality and integrity of personal data and reduce reasonably foreseeable risks of harm to consumers relating to the processing of personal data. The practices shall be appropriate to the volume and nature of the personal data at issue.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.