Table A-1 sets, for Levels A to D, which data items are submitted to the authority (the PHAC, the verification plan, the top-level drawing and the HAS) and the control category (HC1 or HC2) of each; data used for credit but not submitted must be available. For example, hardware requirements, top-level, assembly and installation drawings and hardware/software interface data are HC1 at every level; traceability data is HC2 at every level, with Level C and D needing only requirement-to-test traceability; test coverage of derived or lower-level requirements is not needed at Level D; the design, validation and process assurance plans, standards and conceptual design data fall away at the lower levels. Level A and B functions need independent verification, at the level where design is verified against requirements, by an individual, process or tool independent of the designer (for example independent review of requirements or design, test cases written or reviewed by someone else, independent review of the designer's analysis, a different confirming test, or tool-verified results); organisational separation is not required, and the designer may still run automated tests once independently developed or evaluated.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.