Generated from the locked requirement register

393 promises. Every one has a preview address.

This catalogue maps each locked ID to a concrete screen, workflow, configuration, or diagnostic surface and a deterministic Gate 3 acceptance evidence ID. It does not claim the requirement's later primary implementation gate is complete.

Locked IDs
393 / 393
Families
41 / 41
Module routes
18 / 18
Truth boundary
Fictional simulation
22of 393 mapped
SEC-001SECFixed role templatesCONFIGURATIONsettingsGate 6G03-COV-SEC-001
SEC-002SECCustom role builderCONFIGURATIONsettingsGate 6G03-COV-SEC-002
SEC-003SECBranch/legal-business scopeCONFIGURATIONsettingsGate 6G03-COV-SEC-003
SEC-004SECGranular permissions and approvalsCONFIGURATIONsettingsGate 6G03-COV-SEC-004
SEC-005SECPermanent auditCONFIGURATIONsettingsGate 6G03-COV-SEC-005
SEC-006SECServer-side tenant/legal-business/branch authorisation decisionCONFIGURATIONsettingsGate 23G03-COV-SEC-006
SEC-007SECDatabase-equivalent row isolation and mandatory cross-tenant negative testsCONFIGURATIONsettingsGate 23G03-COV-SEC-007
SEC-008SECTLS 1.2 minimum, TLS 1.3 preferred, and encrypted local/service channelsCONFIGURATIONsettingsGate 23G03-COV-SEC-008
SEC-009SECDatabase/object/backup/local encryption and sensitive field protectionCONFIGURATIONsettingsGate 23G03-COV-SEC-009
SEC-010SECCentral KMS/secret management, rotation, environment separation, and auditCONFIGURATIONsettingsGate 23G03-COV-SEC-010
SEC-011SECMinimal encrypted device-bound offline POS cacheCONFIGURATIONsettingsGate 23G03-COV-SEC-011
SEC-012SECSigned, certificate-bound, allowlisted Device Bridge and Branch HubCONFIGURATIONsettingsGate 23G03-COV-SEC-012
SEC-013SECSeparate append-only tamper-evident business and security logsCONFIGURATIONsettingsGate 23G03-COV-SEC-013
SEC-014SECMandatory secret/PII/financial log redactionCONFIGURATIONsettingsGate 23G03-COV-SEC-014
SEC-015SECSecurity monitoring, anomaly detection, alert routing, and closure auditCONFIGURATIONsettingsGate 23G03-COV-SEC-015
SEC-016SECMalware-scanned, quarantined, tenant-scoped private file handlingCONFIGURATIONsettingsGate 23G03-COV-SEC-016
SEC-017SECMFA/re-authenticated, encrypted, expiring, audited data exportCONFIGURATIONsettingsGate 23G03-COV-SEC-017
SEC-018SECASVS 5.0.0 Level 2 minimum and selected Level 3 release baselineCONFIGURATIONsettingsGate 23G03-COV-SEC-018
SEC-019SECSAST/SCA/secret/IaC/container/DAST/API scans, SBOM, signed artifacts, and rollback gateCONFIGURATIONsettingsGate 23G03-COV-SEC-019
SEC-020SECVulnerability remediation SLA and recurring penetration testsCONFIGURATIONsettingsGate 23G03-COV-SEC-020
SEC-021SECComprehensive authentication/isolation/offline/file/log/restore security acceptance testsCONFIGURATIONsettingsGate 23G03-COV-SEC-021
SEC-022SECSecurity controls are plan-independent integrity requirementsCONFIGURATIONsettingsGate 23G03-COV-SEC-022