Controllers must establish, implement and maintain reasonable administrative, technical and physical data security practices to protect the confidentiality, integrity and accessibility of personal data. The practices must be appropriate to the volume and nature of the personal data at issue.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.