NC-A5-missing-evidence-05 — Named evidence is present, but effectiveness is not shown.
This page follows the certification-audit detailed-report fields. Assessment Results stay the kernel original. Requirement cites the catalog ID and catalog title — not ISO shall-prose. Stage 1/2 is not invented. NC-RP and CAR stay journal citations.
| Clause / control | A.5.20 |
|---|---|
| Area / owner | a5 |
| Requirement | A.5.20 Addressing information security within supplier agreements |
| Finding | A.5.20 Addressing information security within supplier agreements is named in this pack, but there is no effectiveness evidence. Cited policy: CSS. Cited implementation: CSSAQ. |
| Grade | minor |
| Path | Requirement ↔ evidence |
| Procedure | 10.2 |
| Topic | a5 |
| Volume | 1 |
Objective evidence
This pack names a policy or an implementation, but there is no effectiveness evidence. The pointers below are those cited artefacts.
Cited artefacts: CSS, CSSAQ.
Subject in this pack: A.5.20.
No opened file is attached. That is expected when the gap is “nothing in the pack” or “named but not evidenced” — there is no SHA-256 to show until the kernel opens a file.
