Mechanisms exist to ensure all web application content is delivered using cryptographic mechanisms (e.g., TLS).
Does the organization ensure all web application content is delivered using cryptographic mechanisms (e.g., TLS)?