search

CSVV Cybersecurity Verification and Validation

# PROCESS PURPOSE 
The purpose is to specify and verify the cybersecurity requirements, and to validate the cybersecurity goals.

# PROCESS OUTCOMES 
  • O1 Cybersecurity requirements are derived from cybersecurity goals
  • O2 treatment is specified and performed
  • O3 Activities are identified and documented to validate cybersecurity goals and validation results are recorded
  • O4 Traceability is established between the cybersecurity goals and validation results
  • O5 Traceability is established between cybersecurity requirements and goals, and between the cybersecurity requirements and treatment specification

# BASE PRACTICES 
BP1 Specify cybersecurity requirements for the cybersecurity goals. ( O1 )
BP2 Cybersecurity verification measures are specified and performed. ( O2 )
BP3 Cybersecurity validation activities are identified and documented. ( O3 )
BP4 Results of cybersecurity validation activities are recorded. ( O4 )
BP5 Traceability is established ( O5 )

# OUTPUT INFORMATION ITEMS 
15-51 Analysis result ( O5 )
17-00 Requirement ( O1 )
13-19 Review evidence ( O5 )
08-59 Validation Measure ( O3 )
13-24 Validation Results ( O4 )
08-60 Verification Measure ( O2 )
08-58 Verification Measure Selection Set ( O2 )
13-25 Verification Result ( O2 )