The system documentation identifies which system functions and interfaces are allocated to software, and fully defines the host system's functions with their interfaces, its application conditions, its architecture or configuration, hazards to control, safety integrity requirements, the split of requirements with SIL or Basic Integrity allocated to software and hardware, and timing constraints. Software integrity is one of five levels, Basic Integrity up to SIL 4, decided and assessed at system level from the system SIL and the risk of using the software. Software whose functions carry a safety impact below SIL 1 meets at least the Basic Integrity requirements; software with no safety role is still produced under a quality assurance process (Basic Integrity, ISO/IEC/IEEE 90003 or another code of practice). Conformance means showing every requirement is met at the defined level so each subclause objective is achieved. Where a requirement is tied to the integrity level by its wording, a range of techniques is used, chosen with the Annex A tables and recorded in or referenced from the Software Quality Assurance Plan. Not using a technique graded HR needs a recorded rationale for the alternative unless an approved combination from the table is used, and chosen techniques must be shown to be applied correctly. A technique absent from the tables needs a recorded justification of its effectiveness. Compliance is checked by document inspection, supplemented where fitting by other objective evidence, audits and witnessed tests. Software produced under any edition of EN 50128 or of EN 50657 can be treated as compliant rather than as pre-existing software.
This control maps to 4 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.