IVV-CSO-RAAReceiving Assessor Advice
allMAY
Providers MAY ask for and accept advice from their assessor during assessment regarding techniques and procedures that will improve their security posture or the effectiveness, clarity, and accuracy of their verification, validation and reporting procedures, UNLESS doing so is likely to compromise the objectivity and integrity of the assessment.
Who it binds
Which certifications it binds
- Certification type
- 20x · Rev5
- Path
- Program · Agency
Evidence this requirement demands
No requirement-specific artifacts — but the defaults below still apply.
5 default artifacts owed by every FRR requirement
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
Group all, subset CSO of Independent Verification and Validation. See all obligations on /obligations or the full evidence plan on /evidence.