Per SSDF PW group: secure development. Requirements include (a) Design to meet security requirements + threat model + (b) Review the software design + (c) Verify third-party software + dependencies + (d) Reuse existing well-secured software where possible + (e) Implement secure coding practices + (f) Configure for secure defaults + (g) Review + analyze human-readable code + (h) Test executable code + (i) Configure tools.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.