GM1 ATM/ANS.OR.A.050 Facilitation
and cooperation
ED Decision 2019/022/R
AUDITS
— SOFTWARE ASSURANCE PROCESSES BY THE COMPETENT AUTHORITY
(a) The assessment of an effective application of the documented software assurance processes may necessitate a technical evaluation of the evidence and arguments produced for the software assurance by the competent authority when reviewing a notified change. In this context, the service provider should ensure access to the configuration management system for the competent authority, which may need to verify:
(1) the consistency of all the evidence; and
(2) the fact that all the evidence is derived from a known version of the software (i.e. all evidence and arguments are actually available and can be traced without ambiguity to the executable version).
(b) The service provider should:
(1) anticipate the possibility for on-site audits or inspections by the competent authority; and
(2) when evidence and arguments are developed by contracted organisations, include the corresponding rights of the competent authority to assess said organisations during onsite audits or inspections.
Loading collections...