OWASP DevSecOps Maturity Model (DSOMM)
Information Gathering and Monitoring

OWASP DevSecOps Maturity Model (DSOMM) DSOMM-5: Information Gathering, Logging, Monitoring, and Incident Response

Per OWASP DSOMM Information Gathering dimension and operational monitoring: implement observability + detection + response. Requirements include (a) collect security telemetry from application + infrastructure + identity + access layers + (b) implement runtime threat detection + application-layer protections + (c) operate alerting + anomaly detection with triage + investigation workflows + (d) maintain production-to-development feedback loops including security findings + remediation + (e) operate incident response readiness including playbooks + tabletops + on-call + (f) integrate with SIEM + SOC + threat intelligence + (g) align logging retention + handling with regulatory + investigative + governance requirements.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.