All personnel with responsibilities for the software are organised, empowered and capable of fulfilling them. The supplier or developer operates a quality management system compliant with EN ISO 9001 (5.1.2.1); except at Basic Integrity the safety process runs under a safety organisation compliant with EN 50129. An assessor independent of the project is appointed with authority to assess the software and approved by the safety authority; the assessor may belong to the supplier's or customer's organisation only with the safety authority's agreement, totally independent of the project team and reporting to the safety authority. Minimum independence of the Annex B roles is graded: at Basic Integrity one person may act as designer, implementer, verifier and validator; at SIL 1 and 2 one person may verify and validate but may not also design or implement, all may report to the project manager; at SIL 3 and 4 either the verifier and validator are one person independent of the designer and implementer and not reporting through the same project manager, with authority to prevent release, or all are separate persons with the validator outside the project manager's line and holding release authority. Responsibilities for the requirements manager, designer, implementer, tester, verifier, integrator, validator, assessor, project manager and configuration manager are those of Annex B (5.1.2.2 to 5.1.2.14).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.