Six phases, and the third one is where the work is
Kickoff and documentation are administrative. Gap assessment is where the application is actually taken apart, and where the 30 to 90 day remediation window is decided.
Deliverables
Two sets. First, the action tracker following gap analysis. Second, the Report on Validation, the Attestation of Validation, and the Certificate of Validation once final certification is complete.
Validity and revalidation
A listing is valid for three years, with annual revalidation mandatory throughout. Where nothing has changed, a signed AOV is shared with the council. Where the application has changed, each change is classified as high impact, low impact or administrative and the assessor is informed before the AOV is submitted.
The two things you must have first
Application penetration testing
Mandatory for S3. A current validated report has to be available during the audit.
Secure code review
Also mandatory, and separate from the manual review performed during gap assessment.
PCI DSS
If you process rather than build, the Data Security Standard is the one that applies.
