There should be a means to provide assurance that the system is operating as expected and that all of the various controls are correctly implemented and operated.
namespace
SABSA
stereotype
RiskAttribute
softMetric
Independent audit and review against Security Architecture Capability Maturity Model.
hardMetric
Documented standards exist against which to audit.