AUDITS — SOFTWARE ASSURANCE PROCESSES BY THE COMPETENT AUTHORITY
(a)The assessment of an effective application of the documented software assurance processes may necessitate a technical evaluation of the evidence and arguments produced for the software assurance by the competent authority when reviewing a notified change. In this context, the service provider should ensure access to the configuration management system for the competent authority, which may need to verify:
(1)the consistency of all the evidence; and
(2)the fact that all the evidence is derived from a known version of the software (i.e. all evidence and arguments are actually available and can be traced without ambiguity to the executable version).
(b)The service provider should:
(1)anticipate the possibility for on-site audits or inspections by the competent authority; and
(2)when evidence and arguments are developed by contracted organisations, include the corresponding rights of the competent authority to assess said organisations during onsite audits or inspections.