Objective
Ensure COTS release decisions are approved and traceable to the tested version.
Control Activity
Before production use, Compliance verifies that acceptance criteria are met, CORF confirmation is documented, required release sign-off is complete, and the decision identifies the accepted version, scope, conditions and residual risks. A release without complete evidence is blocked and escalated.
Evidence
- Expected evidence: approval record
- Expected evidence: release register entry
- Expected evidence: accepted version record
- Expected evidence: CORF confirmation and residual-risk record where applicable
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample production releases and reconcile approvals to the tested and deployed version
- Testing frequency: before every production release
Relationships
- Requirements: REQ-IT-007 Maintain Software Testing and Release Assurance, REQ-IT-008 Manage Technology Change Acquisition and Outsourced IT Services
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-COTS-005 Approve COTS Release and Acceptance Decision
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented design; runtime effectiveness pending system-derived assessment
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.