Per OWASP ASVS V14: implement secure configuration. Requirements include (a) maintain hardened baseline configurations across application + middleware + runtime + container + cloud infrastructure + (b) implement configuration management with drift detection + remediation + (c) disable unnecessary features + services + endpoints + debug + verbose error messages + (d) implement secure deployment pipeline with infrastructure as code + signed artefacts + (e) apply security headers (HSTS + CSP + X-Content-Type-Options + Referrer-Policy + Permissions-Policy + similar where applicable) + (f) protect secrets via dedicated secret store + (g) maintain CI/CD security including pipeline isolation + artifact integrity + deployment approvals.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.