Silver criterion crypto_verification_private (MUST; group Security, Use basic good cryptographic practices). Criterion text: The software produced by the project MUST, if it supports TLS, perform certificate verification before sending HTTP headers with private information (such as secure cookies). If the software does not use TLS, select "not applicable" (N/A).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.