Traffic from the 3DS Requestor App or from the browser to the 3DS Requestor runs over standard internet protocols and, once 3DS-specific actions begin, a secured link satisfying PCI DSS with at least TLS and server authentication of the requestor; data between a separate 3DS Requestor and 3DS Server is protected at a PCI DSS level with mutual server authentication, and any customer authentication already performed is conveyed in the 3DS Requestor Authentication Information.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.