Purpose
Translate the CBCS software testing guideline into a testable BCMS requirement for managed, risk-based testing and release assurance.
Normative
Bitkaya shall maintain a software testing framework that is directed by management, risk-based, planned, designed with documented test cases, executed in a dedicated test environment, supported by qualified testers, includes security testing and is subject to an ongoing assessment program.
Descriptive
This requirement captures the software testing principles on test policy and strategy, planning, monitoring, test design, dedicated test environment, capability, security testing and ongoing assessment.
Source reference: Provisions and Guidelines for Software Testing.
Assurance Assertions
- Software changes are subject to approved testing controls.
- Risk-based test planning and security testing are performed.
- Test evidence and ongoing assessment records are retained.
Relationships
- Source: SRC-IT-001 CBCS IT Governance, Security, Continuity and Testing Guidelines
- Policy: POL-IT-001 IT and Cybersecurity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-IT-007 Maintain Software Testing and Release Assurance
- Control: CTRL-IT-007 Ensure Software Testing and Release Assurance Is Maintained
- Systems: SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-IT-001 Odoo Automated Compliance Monitoring
- Publications: PUB-KYT-002 Crystal Intelligence Calibration and Change Record, PUB-IT-001 Automated Compliance Monitoring Controls in Odoo SOP, PUB-TRAIN-005 IT Compliance Training, PUB-KYT-001 Odoo Pre-Trade and Post-Trade KYT Controls SOP
Assurance
- Source verified: yes
- Implementation linked: yes
- Wording unambiguous: review
History
- 2026-07-26: Created from SRC-IT-001.
- 2026-07-26: Linked to the IT process, procedure and control set.
- 2026-07-26: Added the missing IT policy metadata mapping.