For 7.1.1;
The following description in “References and details” should be moved to “Verification requirements” of Part A, and subsequent version of RBA’s Code of Conduct needs to be added.
a) URL(s) for publicly available manufacturer commitment to meeting the requirements of this criterion on manufacturer’s website. [ADD: RBA’s Code of Conduct Version 7.0 and/or subsequent versions (including 8.0) meet the manufacturer’s commitment elements of this criterion.]
[ADD: h) Demonstrating RBA membership and conducting the assessment using RBA’s Risk Assessment Platform in combination with Self-Assessment Questionnaire (SAQ) is acceptable evidence for conformance to all of Part A Verification requirements.]
We believe the above-mentioned methodology should be evidence for at least, b), e) and f) of the “Verification requirements”.
For 7.1.2;
“References and details” also refer to “RBA’s Code of Conduct”. As mentioned above, “RBA’s Code of Conduct” should be moved from “References and details” to “Verification requirements” by adding d) as follows:
[ADD: d) RBA’s Code of Conduct, Version 7.0 and/or subsequent versions (including 8.0) meet the elements of this criterion.]
For 7.1.3;
The following description in “References and details” should be moved to “Verification requirements”:
“RBA’s Risk Assessment Platform in combination with Self-Assessment Questionnaire (SAQ) is recognized as an analysis methodology meeting the identification Prioritized Supplier Facilities of “Part A. Assessment for to Determining Determine Prioritized Supplier Facilities in Scope.”
We propose to change the description of “a) of Part A” in “Verification requirements” as follows:
a) Documentation of process to identify Prioritized Supplier Facilities that demonstrates conformity to this criterion. [ADD: RBA’s Risk Assessment Platform in combination with Self-Assessment Questionnaire (SAQ) is recognized as an analysis methodology meeting the identification Prioritized Supplier Facilities of “Part A. Assessment for to Determining Determine Prioritized Supplier Facilities in Scope.]
|