Purpose

Execute functional, integration, security and acceptance testing for a COTS product or update.

Scope

This procedure applies to defect logging, vulnerability review, authentication, encryption, audit log and privileged access checks.

Steps

#ActionDetailsEvidence
1Execute acceptance test casesExecute the approved functional, integration, UAT, OAT, performance and compliance test cases in the controlled environment.Execution record
2Log and manage defectsLog, classify and assign every defect; record retesting and closure evidence.Defect log
3Perform security testingPerform a security product-risk assessment and the proportionate penetration testing, vulnerability scanning and configuration review.Security testing record
4Validate security controlsValidate authentication, encryption, audit logging and privileged-access controls.Security control validation record
5Confirm defects and vulnerabilities resolvedConfirm critical defects are resolved and security vulnerabilities are mitigated within Bitkaya’s approved risk appetite.Defect closure and vulnerability record
6Escalate failed resultsEscalate failed, incomplete or materially deviating results before any release decision.Escalation record

Evidence

  • execution record
  • defect log
  • security testing record
  • escalation or approval record where relevant

Relationships

Implementation

  • Implementation state: current under the approved COTS Acceptance and Testing Manual version 1.0
  • Execution evidence: retained for each test cycle

History

  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.