Objective
Ensure acceptance and security testing are completed before COTS release.
Control Activity
Before production release, Technology and Compliance verify completion of the approved functional, integration, acceptance, operational and security tests; closure of critical defects; mitigation of vulnerabilities within risk appetite; and validation of authentication, encryption, audit logging and privileged access.
Evidence
- Expected evidence: execution record
- Expected evidence: defect log
- Expected evidence: security testing record
- Expected evidence: escalation or approval record where relevant
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample releases and trace planned tests, results, defects, retests and residual-risk decisions
- Testing frequency: before every production release and after material security change
Relationships
- Requirements: REQ-IT-002 Maintain Information Security Management, REQ-IT-007 Maintain Software Testing and Release Assurance
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-COTS-004 Execute COTS Acceptance and Security Testing
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented design; runtime effectiveness pending system-derived assessment
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.