Objective

Ensure COTS risk assessment and test planning are completed before testing begins.

Control Activity

Before testing begins, Technology and Compliance verify that the COTS intake includes product, ICT, legal, compliance, vendor, licensing, support and vulnerability risks; a criticality-based test strategy; documented resources, schedule, entry and exit criteria; and stakeholder approval.

Evidence

  • Expected evidence: risk assessment
  • Expected evidence: test plan
  • Expected evidence: stakeholder sign-off
  • Expected evidence: escalation record where relevant
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample COTS changes and compare approved plans with the mandatory risk and planning criteria
  • Testing frequency: before each new COTS implementation or material change

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented design; runtime effectiveness pending system-derived assessment

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.