Aim: the deployed software still does what is required and keeps its integrity level and dependability in the final environment. Outputs: Software Deployment Manual, Deployment Records and Deployment Verification Report. The Project Manager is responsible for deployment. Before a release is delivered its baseline, including pre-existing and earlier software, is captured and held traceable in configuration management, and the release stays reproducible for the baseline's whole life. The deployment manual gives procedures to identify and install a release correctly. For incremental deployment of single components, facilities that stop incompatible component versions from being activated are highly recommended at SIL 3 and 4 and recommended at SIL 1 and 2. Configuration management prevents harm where different versions of one component must coexist, and change control lets an amended generic software be installed only once it is shown compatible with the existing application data or the data have been revised. A rollback to the previous release is available. The software carries self-identification readable during and after loading, which should give software and configuration data versions and product identity, with the release information recommended to be protected by error detecting codes. A deployment record proves, by reading that self-identification, that the intended software was loaded; it is filed with the delivered system documents and forms part of commissioning and acceptance. Deployed software is traceable to each installation it went to. The software supplies diagnostic information for fault monitoring. The Verifier checks the deployment manual and records for readability, traceability, specific content and consistency. The package includes measures to prevent or detect corruption of executable code or data in storage, transfer, transmission or copying, with coding of the executable recommended as part of the load integrity check.
This control maps to 8 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 8 it maps to, and the evidence behind each claim, over MCP and REST.