Insights / 05

Trust decisions are made about operating capabilities, not isolated repositories, models, or test reports.

Independent software assuranceSM / 05.34

SecondMark position

Assurance should follow the claim across every component, dependency, person, environment, and control required to make it true in practice.

The examination is bounded to defined claims, a versioned system, and evidence that can be traced to the state under review. Any material exclusion or uncertainty remains visible in the conclusion.

01

Core questions

What the examination needs to establish.

  1. 01

    Where is the claim implemented?

  2. 02

    Which dependencies are necessary for it to hold?

  3. 03

    What human actions complete the control path?

  4. 04

    Which runtime states can invalidate it?

02

Evidence model

Evidence is assembled around the claim—not the folder structure.

01

Explicit definitions

Collected, attributed, challenged, and connected to the exact system boundary under examination.

02

Reasoned assurance principles

Collected, attributed, challenged, and connected to the exact system boundary under examination.

03

Practical system implications

Collected, attributed, challenged, and connected to the exact system boundary under examination.

04

Boundaries and counterexamples

Collected, attributed, challenged, and connected to the exact system boundary under examination.

Intended outcome

A shift from artifact-centered review to evidence connected across the actual system boundary.

A sharper decision frameQuestions for system stewardsPractical next steps
03

Professional boundary

What an opinion does—and does not—mean.

It provides

A traceable independent conclusion on defined claims, grounded in the evidence and system state examined.

It does not provide

A guarantee that failure is impossible, a permanent certification, or a conclusion beyond the stated scope and validity conditions.