NC-SUPPLIER-missing-evidence-03 — Named evidence is present, but effectiveness is not shown.
This page follows the certification-audit detailed-report fields. Assessment Results stay the kernel original. Requirement cites the catalog ID and catalog title — not ISO shall-prose. Stage 1/2 is not invented. NC-RP and CAR stay journal citations.
| Clause / control | A.5.21 |
|---|---|
| Area / owner | supplier |
| Requirement | A.5.21 Managing information security in the ICT supply chain |
| Finding | A.5.21 Managing information security in the ICT supply chain is named in this pack, but there is no effectiveness evidence. Cited implementation: CSSAQ. |
| Grade | minor |
| Path | Requirement ↔ evidence |
| Procedure | 10.2 |
| Topic | supplier |
| Volume | 1 |
Objective evidence
This pack names a policy or an implementation, but there is no effectiveness evidence. The pointers below are those cited artefacts.
Cited artefacts: CSSAQ.
Subject in this pack: A.5.21.
No opened file is attached. That is expected when the gap is “nothing in the pack” or “named but not evidenced” — there is no SHA-256 to show until the kernel opens a file.
