Per OWASP DSOMM Metrics and Improvement: measure security maturity + drive continuous improvement. Requirements include (a) define security metrics covering culture + implementation + build + test + monitoring dimensions + (b) measure DSOMM maturity levels per dimension + per sub-area + over time + (c) operate security risk scoring + dashboards visible to engineering + product + leadership + (d) implement compliance monitoring + reporting + (e) drive continuous improvement via retrospective + post-incident review + benchmark + (f) align metrics to business outcomes + with regular review + and improvement planning.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.