Purpose
Execute functional, integration, security and acceptance testing for a COTS product or update.
Scope
This procedure applies to defect logging, vulnerability review, authentication, encryption, audit log and privileged access checks.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Execute acceptance test cases | Execute the approved functional, integration, UAT, OAT, performance and compliance test cases in the controlled environment. | Execution record |
| 2 | Log and manage defects | Log, classify and assign every defect; record retesting and closure evidence. | Defect log |
| 3 | Perform security testing | Perform a security product-risk assessment and the proportionate penetration testing, vulnerability scanning and configuration review. | Security testing record |
| 4 | Validate security controls | Validate authentication, encryption, audit logging and privileged-access controls. | Security control validation record |
| 5 | Confirm defects and vulnerabilities resolved | Confirm critical defects are resolved and security vulnerabilities are mitigated within Bitkaya’s approved risk appetite. | Defect closure and vulnerability record |
| 6 | Escalate failed results | Escalate failed, incomplete or materially deviating results before any release decision. | Escalation record |
Evidence
- execution record
- defect log
- security testing record
- escalation or approval record where relevant
Relationships
- Requirements: REQ-IT-002 Maintain Information Security Management, REQ-IT-007 Maintain Software Testing and Release Assurance
- Policy: POL-COTS-001 Commercial Off-The Shelf Software Acceptance and Testing Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-COTS-004 Ensure COTS Acceptance and Security Testing Is Completed
Implementation
- Implementation state: current under the approved COTS Acceptance and Testing Manual version 1.0
- Execution evidence: retained for each test cycle
History
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.