Aim: for SIL 1 to 4, evaluate how far the lifecycle processes and outputs make the software meet its specified requirements and form a judgement on fitness for purpose. Basic Integrity software meets the standard's requirements but needs no assessment. The Assessor, independent in the sense of 5.1.2.6 with the authority of 5.1.2.7, works from the System and Software Requirements Specifications and any other needed document, with access to all project documentation throughout. Software already carrying another assessor's report need not be reassessed, but the Assessor confirms fitness for the intended use and environment and that the earlier assessment reached at least the required level. The Software Assessment Plan (a documented generic plan or procedure may serve) covers scope, activities and how they link to engineering steps, documents considered, pass and fail criteria with the handling of non-conformances, and the required content and form of the report. The Assessor assesses: fitness for purpose and correct response to safety issues from the system requirements; whether a suitable Annex A technique set was chosen and applied for the phase and level, how widely each was applied and whether properly; the configuration and change management arrangements and evidence they are used; staff competence against Annex B and the organisation against 5.1; deviations, non-compliances and non-conformities affecting safety-related application conditions and whether the project's justification holds; and the verification and validation work and evidence. The Assessor agrees the scope and content of the validation plan, including whether the Assessor attends testing, may audit, inspect and witness tests at any time and may ask for more verification and validation. The Software Assessment Report meets the plan, gives conclusions and recommendations, summarises the recorded assessment activities, and lists every non-conformity with the standard and its judged impact.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.