Per OWASP MASVS v2 MASVS-NETWORK: secure network communication for mobile apps. Requirements include (a) use TLS 1.2 or later with strong cipher suites for all sensitive network communications + (b) implement certificate pinning where appropriate + with secure pin management + rotation + (c) validate certificates properly + reject invalid + expired + untrusted certificates + (d) protect against TLS downgrade + man-in-the-middle attacks + (e) implement App Transport Security (iOS) + Network Security Config (Android) policies + (f) protect against insecure network configurations including HTTP fallback + cleartext + weak ciphers + (g) implement appropriate timeouts + retries + circuit breaker patterns.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.