search

SEC.3 Risk Treatment Verification

# PROCESS PURPOSE 
The purpose is to confirm that the implementation of the design and of the components comply with the cybersecurity , the refined architectural design and detailed design.

# PROCESS OUTCOMES 
  • O1 Risk treatment measures are developed.
  • O2 measures are selected according to the release scope.
  • O3 The implementation of the design and the of the components is verified. results are recorded.
  • O4 and bidirectional are established between the risk treatment measures and the cybersecurity , as well as between the risk treatment measures and the refined architectural design, detailed design and . Bidirectional is established between the results and the risk treatment measures.
  • O5 The results of the risk treatment are summarized and communicated to all affected parties.

# BASE PRACTICES 
BP1 Specify risk treatment verification measures. ( O1 )
BP2 Select verification measures. ( O2 )
BP3 Perform risk treatment verification activities. ( O3 )
BP4 Ensure consistency and establish bidirectional traceability. ( O4 )
BP5 Summarize and communicate results. ( O5 )

# OUTPUT INFORMATION ITEMS 
13-52 Communication Evidence ( O5 )
13-51 Consistency Evidence ( O4 )
08-60 Verification Measure ( O1 )
03-50 Verification Measure Data ( O3 )
08-58 Verification Measure Selection Set ( O2 )
15-52 Verification Results ( O3 )