Security verification
Produce objective evidence that security requirements and controls are implemented correctly.
PSLF-04G4Verification acceptedPhase 5 of 9
Gate
G4
Pending
Verification accepted
Target date
13 Nov 2026
Gate review
Open blockers
0
none recorded
Accountable
Security Reviewer
Engineering resolves findings
Verify requirements and controls through review, analysis, automated testing, and independent penetration testing.
- Testing is risk-based and reproducible.
- Failures cannot close without disposition and independent retest.
- Approved verification-ready baseline
- PSTP and qualified test environment
- Implemented controls and traceability
- 1Run requirement and control verification
- 2Perform SAST, DAST, composition analysis, fuzzing, abuse-case tests, protocol tests, and penetration testing as applicable
- 3Record defects and deviations
- 4Reassess risk and repeat affected verification after changes
- Product Security Test Plan
- Product Security Verification Report
- Penetration-test report
- Updated PSRTM, PSRA, PSPR, VMR, and evidence records
- All required tests executed or formally deviatedPending
- Critical/high findings resolved or accepted by authorityPending
- Independent review completePending
- Every control has objective evidencePending
- Accountable
- Security Reviewer accountable and independent from implementation
- Supporting
- Engineering resolves findings
- Control (pending)
- Acceptance criteria (pending)
- Test case (pending)
- Result (pending)
- Evidence (pending)
- Finding (pending)
- Retest (pending)
- Control verification coverage
- First-pass effectiveness
- Retest cycle time