Complexity is judged by how feasible it is to reach acceptable verification coverage by deterministic means, examining the hardware level by level (integrated circuit, board, LRU) including functions that testing may not reach, for example unused modes of multi-use devices and hidden states in sequential machines. An item is simple only if a comprehensive mix of deterministic tests and analyses suited to its assurance level can show correct functional performance in every foreseeable operating condition with no anomalous behaviour; otherwise it is complex, and an item built only from simple items may still be complex. An ASIC or PLD may still count as simple if it meets that test. For complex items the means of design assurance should be settled early with the certification authority. Simple items still need documented verification and configuration management, with lighter design documentation.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.