Gold criterion hardened_site (MUST; group Security, Secured delivery against man-in-the-middle (MITM) attacks). Criterion text: The project website, repository (if accessible via the web), and download site (if separate) MUST include key hardening headers with nonpermissive values.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.