OWASP DevSecOps Maturity Model (DSOMM)
Test and Verification

OWASP DevSecOps Maturity Model (DSOMM) DSOMM-4: Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

Per OWASP DSOMM Test and Verification dimension: implement comprehensive security testing. Requirements include (a) integrate Static Application Security Testing (SAST) in CI/CD with developer feedback + tuning + (b) operate Dynamic Application Security Testing (DAST) against running applications + APIs + (c) implement Interactive Application Security Testing (IAST) where appropriate + (d) operate Software Composition Analysis (SCA) for dependency vulnerabilities + license issues + (e) implement API security testing covering OWASP API Top 10 + business logic + (f) operate fuzz testing for protocol + data parsing + (g) conduct penetration testing + bug bounty + red team activities + (h) maintain security test cases in CI pipelines + with regression coverage.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.