Per OWASP DevSecOps Maturity Model (DSOMM) Culture and Organization dimension: establish organisational structures + governance + education + collaboration + that embed security into DevOps culture. Requirements include (a) maintain documented security governance structures with defined roles + responsibilities + accountability + (b) operate a security champions programme embedding security advocates within product + engineering teams + (c) implement cross-team collaboration including security + development + operations + product + (d) deliver security training programmes including role-based training + secure coding + awareness + tooling proficiency + (e) maintain security policy + enforcement including exception management + (f) measure cultural maturity via metrics including training completion + champion coverage + security advocate engagement.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.