Where the applicant relies on independent assessment of a tool's output, it proposes an assessment that verifies the output is correct and justifies that it covers the output sufficiently, with completeness judged against the design, implementation or verification objectives the tool serves. Tool identification includes the operating environment and revision, and the process and purpose the tool supports are identified. Code coverage tools are excluded from assessment only when used to show code was exercised by requirements-based tests; a tool that generates tests and uses coverage to decide when requirements verification is complete is a verification tool.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.