SA-11(3) - Developer Testing and Evaluation | Independent Verification of Assessment Plans and Evidence
(a) Require an independent agent satisfying [Assignment: organization-defined independence criteria] to verify the correct implementation of the developer security and privacy assessment plans and the evidence produced during testing and evaluation; and
(b) Verify that the independent agent is provided with sufficient information to complete the verification process or granted the authority to obtain such information.
Independent verification of assessment plans and evidence is especially important for space missions, where each discovered vulnerability can mean the difference between a fully functional asset and a multi-million-dollar liability. By having external assessors or third-party experts witness security tests, programs gain confidence that developer blind spots do not bias testing. For instance, the assessors might confirm using realistic threat scenarios—like replay attacks on the RF uplink or attempts to corrupt flight software with malformed command packets. Once the evaluation concludes, they can certify that all test findings, videos, and logs accurately represent the spacecraft's real-world resilience. This extra validation step also ensures that any residual risks are well-understood and endorsed by the authorizing official before launch, ultimately bolstering stakeholder trust in the platform's cyber readiness.