2 results found
-
Internal Inheritance
12.2.1: Internal Inheritance, “Only full cross-version control inheritance is supported when using internal inheritance.” Comment: Why not allow partial internal inheritance? (Example: For a large entity with many business units, the scope of the assessment may be broken up into Year 1 and Year 2 looking at different sets of applications, however they still leverage the same SFTP/site server. We should be able to test once in Year 1 and then Partially inherit in Year 2 (control example: Transmission encryption. The separate part is in-scope applications, the same part is the SFTP site).
1 vote -
Inheritance section 12.2.5 lists the Targeted Assessment as a qualified inheriting assessment type.
The Targeted assessment type should not be listed in section 12.2.5 because can't produce a validated assessment.
1 vote