Artifacts & acronyms
Canonical registry of 22 controlled terms under release FR-2026.1.
Canonical terms
22
controlled vocabulary
Effective
22
100%
under FR-2026.1
Retired aliases
9
search only
- CBOMPSLF-03Cybersecurity Bill of Materials
- Owner role
- Engineering Manager
- CSPPSLF-06Customer Security Package
- Owner role
- Release Manager
- CVDPPSLF-07Coordinated Vulnerability Disclosure Policy
- Owner role
- PSIRT Lead
- EOLSPPSLF-08End-of-Life Security Plan
- Owner role
- Portfolio Owner
- FARPSLF-00Framework Applicability Record
- Owner role
- Regulatory Intelligence
- PMPPSLF-07Patch Management Plan
- Owner role
- PSIRT Lead
- PSAAPSLF-00Product Security Applicability Assessment
- Owner role
- Product Owner
- PSADPSLF-02Product Security Architecture Description
- Owner role
- System Architect
- PSCGPSLF-03Product Security Configuration Guide
- Owner role
- Engineering Manager
- PSIRPPSLF-07Product Security Incident Response Plan
- Owner role
- PSIRT Lead
- PSLFFramework-wideProduct Security Lifecycle Framework
- Owner role
- Framework Governance Board
- PSMPPSLF-01Product Security Management Plan
- Owner role
- Security Lead
- PSPRPSLF-02Product Security and Privacy Requirements
- Owner role
- Security Architect
- PSRAPSLF-02 onwardProduct Security Risk Assessment
- Owner role
- Security Lead
- PSRMRPSLF-06Product Security Risk Management Report
- Owner role
- Security Lead
- PSRTMPSLF-02 onwardProduct Security Requirements Traceability Matrix
- Owner role
- Security Lead
- PSTPPSLF-04Product Security Test Plan
- Owner role
- Security Reviewer
- PSVALRPSLF-05Product Security Validation Report
- Owner role
- Product Owner
- PSVRPSLF-04Product Security Verification Report
- Owner role
- Security Reviewer
- SBOMPSLF-03Software Bill of Materials
- Owner role
- Engineering Manager
- VMPPSLF-07Vulnerability Management Plan
- Owner role
- PSIRT Lead
- VMRPSLF-03 onwardVulnerability Management Register
- Owner role
- Security Lead
22 canonical terms
Product Security Risk Assessment
PSRA · ART-0006Effective
- Registry state
- Effective
- Produced in
- PSLF-02 onward
- Owner role
- Security Lead
- Approver roles
- Security Reviewer, Clinical Safety / Risk Authority
- Purpose
- Threats, risks, controls, residual risk
- Migration note
- Retained; title standardized
Minimum governed content
- Assets, trust boundaries, threat scenarios, hazardous situations
- Method version, factor values, inherent and residual scores
- Treatment decisions with owners and acceptance authority
- Controlled knowledge
- Draft (pending)
- In Review (pending)
- Approved (pending)
- Effective (pending)
- Superseded (pending)
- Retired (pending)
- Lifecycle deliverable
- Not Started (pending)
- Draft (pending)
- In Review (pending)
- Changes Required (pending)
- Approved (pending)
- Effective (pending)
- Threat / risk
- Proposed (pending)
- Confirmed (pending)
- Treatment Planned (pending)
- Implemented (pending)
- Retest (pending)
- Accepted (pending)
- Closed (pending)
- Vulnerability
- Detected (pending)
- Triaged (pending)
- Affected / Not Affected (pending)
- Remediation Planned (pending)
- Fixed (pending)
- Verified (pending)
- Disclosed / Closed (pending)
- Exception
- Requested (pending)
- Under Review (pending)
- Approved / Rejected (pending)
- Active (pending)
- Expiring (pending)
- Closed (pending)
- Incident
- Reported (pending)
- Validated (pending)
- Contained (pending)
- Investigating (pending)
- Remediating (pending)
- Monitoring (pending)
- Closed (pending)