Per OWASP SAMM v2 Verification business function: verify security through assessment + testing. Security Practices: (1) Architecture Assessment including architecture validation + compliance + (2) Requirements-Driven Testing including security testing per requirements + misuse + abuse case testing + (3) Security Testing including scalable baseline (automated SAST + DAST + SCA + dependency scanning) + deep understanding (penetration testing + red team). Requirements include (a) conduct architecture assessment validating implementation against design + secure architecture + (b) implement requirements-driven testing including misuse + abuse case testing + (c) operate scalable baseline security testing via automated SAST + DAST + SCA + IAST in CI/CD + (d) conduct penetration testing + red team + bug bounty for deep understanding + (e) maintain test coverage + measurement + remediation tracking + (f) integrate findings into defect management.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.