Per OWASP SAMM v2 Implementation business function: secure implementation practices. Security Practices: (1) Secure Build including build process security + software dependencies management + (2) Secure Deployment including deployment process security + secret management + (3) Defect Management including defect tracking + metrics + remediation prioritisation. Requirements include (a) maintain secure build process including signed artefacts + isolated build environments + integrity verification + (b) maintain software dependencies inventory including SBOM + vulnerability scanning + provenance verification + (c) maintain secure deployment process including artifact signing + deployment approvals + rollback + (d) operate secrets management including dedicated secret store + rotation + access control + (e) maintain defect tracking + categorisation + metrics including time-to-remediate + (f) prioritise remediation based on risk.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.