Objective

Ensure COTS release decisions are approved and traceable to the tested version.

Control Activity

Before production use, Compliance verifies that acceptance criteria are met, CORF confirmation is documented, required release sign-off is complete, and the decision identifies the accepted version, scope, conditions and residual risks. A release without complete evidence is blocked and escalated.

Evidence

  • Expected evidence: approval record
  • Expected evidence: release register entry
  • Expected evidence: accepted version record
  • Expected evidence: CORF confirmation and residual-risk record where applicable
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample production releases and reconcile approvals to the tested and deployed version
  • Testing frequency: before every production release

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented design; runtime effectiveness pending system-derived assessment

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.