Per CISA Secure by Design Principle 1: take ownership of customer security outcomes. Requirements include (a) Secure by Default Configuration + (b) Eliminate Default Passwords + (c) Free Security Features for All Tiers + (d) Automatic Security Updates + (e) Reduce hardened configurations as buyer responsibility + (f) maintain transparency on security claims.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.