Per CISA Secure by Design Principle 3: organizational structure. Requirements include (a) Senior Leader Accountability for product security + (b) Security Engineers Embedded in Product Teams + (c) Internal Cybersecurity Sales Force for product security + (d) Maintain Security Within the Lifecycle including legacy + (e) Memory Safety Roadmap.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.