-
-
Notifications
You must be signed in to change notification settings - Fork 68
Open
Description
The ability to optionally supplement the BOM with results of human analysis and opinion is required for moderate to high assurance use cases.
Examples include:
- Analysis of the accuracy of each components data as well as the accuracy of the BOM in its entirety.
- Analysis of the completeness of each components data as well as the completeness of the BOM in its entirety.
- Analysis and determination of the completeness and accuracy of each components inclusions, dependencies, provenance and pedigree. Assertions, known unknowns, etc.
- Analysis of the tools and methods used to create the BOM.
Each analysis should attribute decisions to the people, processes, or machines that made them, timestamps, and signatures, forming an audit trail.