Security Layer 3 Applications per X.805 Clause 7.3: The Applications Security Layer addresses requirements of network-based applications accessed by service provider customers. These applications are enabled by the network services and include both consumer-facing applications and B2B applications running over the service provider network. (1) Application Layer Components: (a) Basic Applications - Email (SMTP + IMAP + POP3 + Exchange) + Web Browsing (HTTP + HTTPS) + File Transfer (FTP + SFTP + FTPS + WebDAV); (b) Directory Services - LDAP + Active Directory + DAP X.500; (c) Voice/Video - VoIP + Video Conferencing (Zoom + Teams + WebEx + Google Meet) + WebRTC; (d) Messaging Apps - IM + WhatsApp + Signal + Telegram + iMessage + Discord + Slack + Teams; (e) E-Commerce - Web stores + Payment processing + Subscription services + Auctions + Marketplaces; (f) Mobile Apps - iOS + Android + Hybrid; (g) Web Applications - SaaS + PaaS + Single-Page Applications (SPA) + Progressive Web Apps (PWA); (h) APIs - REST + GraphQL + gRPC + SOAP + WebSocket + Webhook; (i) Microservices - Service Mesh + Container-native; (j) Office Collaboration - Microsoft 365 + Google Workspace + Slack + Notion + Asana + Trello; (k) Industry-Specific - Banking + Healthcare + Retail + Government + Education; (l) Streaming + Media - IPTV + OTT + CDN + Live streaming + VOD; (m) IoT/M2M Applications + Smart Cities + Connected Vehicles; (n) AI/ML Applications - LLMs + Chatbots + Recommendation Systems + Computer Vision; (o) Gaming Applications - Online + Multiplayer + Cloud Gaming. (2) Applications Layer Security Per Dimension: (a) Access Control - application-level authorization + RBAC + ABAC + permissions + roles; OAuth scopes + OpenID Connect; (b) Authentication - user authentication + MFA + SSO + OIDC + SAML + Passkeys + federated identity; (c) Non-Repudiation - signed emails (S/MIME + DKIM) + signed PDFs + signed transactions + audit trails + blockchain anchoring; (d) Data Confidentiality - end-to-end encryption (S/MIME + PGP for email + Signal Protocol for IM + WhatsApp + iMessage E2EE); + TLS for transport; database encryption; (e) Communication Security - HTTPS + WSS + secure WebSocket + secure RPC; (f) Data Integrity - application data integrity + transaction integrity + database constraints + business rule validation + checksums + signed payloads; (g) Availability - application HA + autoscaling + load balancing + WAF + DDoS protection + microservices resilience patterns; (h) Privacy - application privacy controls + cookie consent + GDPR DSAR + Privacy by Design + data minimization + permission system. (3) Application Layer Specific Security: (a) Web Application Security per OWASP Top 10 - Injection + Broken Authentication + Sensitive Data + XXE + Broken Access Control + Security Misconfiguration + XSS + Insecure Deserialization + Using Components with Known Vulnerabilities + Insufficient Logging; (b) API Security per OWASP API Top 10 - Broken Object Level Authorization + Broken Authentication + Excessive Data Exposure + Lack of Resources and Rate Limiting + Broken Function Level Authorization + Mass Assignment + Security Misconfiguration + Injection + Improper Assets Management + Insufficient Logging; (c) Mobile Application Security per OWASP MASVS + Mobile Top 10; (d) Container Application Security per OWASP Docker Top 10; (e) Cloud-Native Application Security per OWASP Cloud-Native Top 10; (f) Web3 Security per OWASP Smart Contract Top 10; (g) LLM Application Security per OWASP LLM Top 10. (4) Email Security: (a) DKIM DomainKeys Identified Mail - sender domain signing; (b) SPF Sender Policy Framework - sender IP authorization; (c) DMARC Domain-based Message Authentication Reporting Conformance - policy + reporting; (d) BIMI Brand Indicators for Message Identification; (e) S/MIME / OpenPGP end-to-end encryption; (f) TLS Reporting (TLS-RPT) + MTA-STS Mail Transfer Agent Strict Transport Security; (g) ARC Authenticated Received Chain; (h) Anti-spam + Anti-phishing + Email Threat Protection. (5) Web Security: (a) HTTPS + HSTS HTTP Strict Transport Security + Preload List; (b) Content Security Policy (CSP); (c) X-Frame-Options + X-Content-Type-Options + Referrer-Policy + Permissions-Policy; (d) CORS Cross-Origin Resource Sharing; (e) Subresource Integrity (SRI); (f) Web Application Firewall (WAF) per OWASP CRS Core Rule Set; (g) RASP Runtime Application Self-Protection; (h) Bot Management + reCAPTCHA + hCaptcha + Turnstile; (i) Secure SDLC + DevSecOps + Shift-Left; (j) SAST + DAST + IAST + SCA Software Composition Analysis + Secret Scanning. (6) API Security: (a) OAuth 2.0 + OpenID Connect; (b) API Gateway (Kong + Apigee + AWS API Gateway + Azure APIM + Tyk); (c) Rate Limiting + Throttling + Quota; (d) WAF for API + WAAP Web Application and API Protection; (e) mTLS for API + Service Mesh (Istio + Linkerd + Consul); (f) JWT signing + verification + key rotation; (g) API Schema validation (OpenAPI Spec); (h) GraphQL Security per OWASP GraphQL Cheat Sheet; (i) gRPC Security with TLS + mTLS + JWT. (7) Identity and Access Management for Applications: (a) IdP Identity Provider (Okta + Auth0 + Microsoft Entra ID + Ping + Google Identity + Keycloak); (b) Federated SSO via SAML + OIDC; (c) Customer IAM (CIAM); (d) Workforce IAM; (e) Privileged Access Management (PAM) for app admins; (f) Zero Trust Identity + Continuous Verification. (8) Threats per X.805 Table 1 mitigated at Applications: All 5 threats mitigated. (9) Standards: (a) ISO/IEC 27001 A.14 / A.8.25-8.34 (2022) System Acquisition Development + Maintenance; (b) ISO/IEC 27034 Application Security; (c) NIST SP 800-95 Web Services + SP 800-115 Testing + SP 800-218 SSDF Secure Software Development Framework; (d) NIST SSDF v1.1 EO 14028; (e) OWASP ASVS + Top 10 + API Top 10 + MASVS + LLM Top 10 + CRS; (f) PCI DSS Req 6 Secure Software + 8 Authentication; (g) ENISA Good Practices for Application Security; (h) IETF RFC 6749 OAuth 2.0 + 7519 JWT + 8252 OAuth Native Apps + 9101 OAuth 2.1 + RFC 5321 SMTP + 6376 DKIM + 7208 SPF + 7489 DMARC; (i) ITU-T X.1500-series Cybersecurity. Coordinates with X.805 Layer 1/2 + Plane 1/2/3 + 8 Dimensions + Threats All-5 + OWASP + ISO/IEC 27034 + NIST SSDF + 800-95 + IETF OAuth 2.0 + OIDC + SAML + DKIM + DMARC + SPF + ITU-T X.1500 + 3GPP TS 33.117 SCAS. ITU-T X.805 Security Layer 3 Applications applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.