OWASP SAMM
Governance

OWASP SAMM OWASPSAMM-1: Governance: Strategy, Policy, Compliance, Education, Champions

Per OWASP SAMM v2 Governance business function: establish strategic + policy + education foundations. Security Practices: (1) Strategy and Metrics including security strategy + application risk profile + maturity measurement + (2) Policy and Compliance including policy maintenance + standards alignment + compliance tracking + (3) Education and Guidance including security awareness + training delivery + role-based content + security champions programme + secure SDLC documentation. Requirements include (a) maintain documented security strategy aligned to business objectives + with measurement + (b) maintain application risk profiles supporting prioritisation + (c) define + maintain security policies + standards + with compliance tracking + (d) deliver education aligned to roles + measure effectiveness + (e) operate security champions programme + (f) integrate compliance obligations (regulatory + contractual + internal) into governance.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.