Purpose

Retain acceptance evidence and perform ongoing testing for COTS updates, patches and periodic reviews.

Scope

This procedure applies to repository maintenance, regression testing and periodic evidence review.

Steps

#ActionDetailsEvidence
1Store acceptance evidenceStore risk assessments, test plans, test cases, results, defect records, security evidence, proportionality decisions and approvals in the COTS Acceptance Repository.Repository record
2Perform regression testingPerform and document regression testing for every applicable patch, update and release.Regression test record
3Conduct periodic TMMi assessmentsConduct periodic TMMi lightning-scan assessments for Internal Audit and retain the results and remediation actions.TMMi assessment record
4Arrange external auditArrange an external audit or TMMi quick scan at least every three years unless a documented risk-based decision requires an earlier review.External audit record
5Verify repository completenessVerify repository completeness, access, retention and traceability during the annual framework review.Annual review record
6Escalate ongoing-testing gapsEscalate gaps in ongoing testing, assessment or evidence retention.Escalation record

Evidence

  • repository record
  • regression test record
  • periodic review or external assessment record

Relationships

Implementation

  • Implementation state: current under the approved COTS Acceptance and Testing Manual version 1.0
  • Execution evidence: retained for each release and periodic assessment

History

  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.