Per OWASP ASVS V1: ensure verified application architecture + secure design + threat modelling. Requirements include (a) maintain documented secure software development lifecycle (SDLC) including security activities at requirements + design + implementation + testing + release phases + (b) conduct threat modelling at design + revise on significant change + maintain documented threat model output + (c) maintain a documented secure architecture with defined trust boundaries + components + data flows + (d) maintain authentication + session management + access control architecture aligned to the rest of ASVS + (e) maintain shared component + library + service inventory with managed dependency lifecycle + (f) implement secure design principles (defense in depth + least privilege + fail securely + complete mediation + secure defaults).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.