Objective
Ensure staff training, monitoring and framework improvement remain active.
Control Activity
At least annually, Compliance verifies role-based COTS testing training and its effectiveness, reviews approved KPIs and KRIs, confirms material deviations and quality gaps were reported to the Boards, and tracks lessons-learned actions to closure.
Evidence
- Expected evidence: training record
- Expected evidence: monitoring report
- Expected evidence: lessons learned or improvement record
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: inspect annual training evaluation, monitoring reports, Board reporting and action closure
- Testing frequency: annual and after a material testing incident
Relationships
- Requirements: REQ-IT-001 Maintain IT Governance and Oversight, REQ-IT-007 Maintain Software Testing and Release Assurance
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-COTS-007 Manage COTS Training, Monitoring and Continuous Improvement
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented design; runtime effectiveness pending system-derived assessment
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.