Web applications shall be designed, developed and operated according to OWASP-aligned secure practices and tested against application-layer threats.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.