Skip to content

Add Security Assurance Profiles as Section 3.3 of MCP Security Whitepaper#73

Open
nik-kale wants to merge 2 commits intocosai-oasis:feat/mcp-security-v2from
nik-kale:mcp-security-assurance-profiles
Open

Add Security Assurance Profiles as Section 3.3 of MCP Security Whitepaper#73
nik-kale wants to merge 2 commits intocosai-oasis:feat/mcp-security-v2from
nik-kale:mcp-security-assurance-profiles

Conversation

@nik-kale
Copy link
Copy Markdown
Contributor

@nik-kale nik-kale commented Apr 8, 2026

Summary

Integrates MCP Security Assurance Profiles directly into model-context-protocol-security.md as Section 3.3, placed after Controls and Mitigations (3.2) and before Conclusion (4). This replaces the earlier standalone file under practical-guides/.

Defines four graduated security assurance levels (L1 Sandbox, L2 Internal, L3 Production, L4 Regulated) across eight control dimensions:

  1. Identity and Authentication
  2. Authorization and Delegation
  3. Transport and Network Security
  4. Isolation and Sandboxing
  5. Logging and Observability
  6. Supply Chain and Lifecycle
  7. Tool Definition, Input, and Output Integrity
  8. Session and Discovery Security

Each control maps back to MCP-T1 through MCP-T12 threat categories and cross-references the OWASP MCP Top 10. Deployment pattern mapping aligns with Appendix 6.1.

No existing sections were renumbered. Sections 4 (Conclusion), 5 (Contributors), and 6 (Appendix) remain unchanged.

Changes

  • Deleted practical-guides/mcp-security-assurance-profiles.md (moved into whitepaper)
  • Modified model-context-protocol-security.md:
    • Added Section 3.3 with all assurance profile content
    • Updated Table of Contents with 3.3 entries
    • Added contributor (Nik Kale, Cisco)

Related

Define four graduated assurance levels (L1-L4) for MCP deployments
with concrete control requirements across eight security dimensions.
Maps to MCP-T1 through MCP-T12 threat categories and DP1-DP3
deployment patterns from the V1 whitepaper, with cross-references
to the OWASP MCP Top 10.

Refs cosai-oasis#36

Made-with: Cursor
@CLAassistant
Copy link
Copy Markdown

CLAassistant commented Apr 8, 2026

CLA assistant check
All committers have signed the CLA.

@nik-kale nik-kale changed the base branch from main to feat/mcp-security-v2 April 8, 2026 02:53
Move assurance profiles content from standalone practical-guides/ file
into the main whitepaper (model-context-protocol-security.md) as a new
Section 3.3, placed after Controls and Mitigations (3.2). Adds four
graduated security levels (L1-L4) across eight control dimensions with
threat coverage mapping to MCP-T1 through MCP-T12 and OWASP MCP Top 10.
Resolves cosai-oasis#36
@nik-kale nik-kale changed the title Add MCP Security Assurance Profiles (Issue #36) Add Security Assurance Profiles as Section 3.3 of MCP Security Whitepaper Apr 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants