The PHAC, once approved, is the agreement between applicant and authority on the processes, activities and evidence for the hardware aspects of certification, and may sit within another plan. It covers a system overview (functions, failure conditions, architecture, allocation to hardware and software); a hardware overview (functions, items, architecture, new technologies, fail-safe, fault tolerance, redundancy and partitioning); certification considerations (certification basis, means of compliance, assurance level per function with justification from the hardware safety assessment and potential failure conditions, and the FFPA summary or plan where applicable); the hardware design life cycle (procedures, methods, standards, activities, sequencing, transition criteria, responsibilities, tools, feedback between processes); the life cycle data to be produced or made available; additional considerations (previously developed hardware, COTS, service experience, tools, Appendix B methods); alternative methods with justification; and the certification schedule.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.