Implement appropriate technical and organisational measures proportionate to the risk of processing, including access control, encryption in transit and at rest, logging, secure development, vulnerability management and physical security of facilities holding personal information.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.