"Verified" means
a passing test exists.
Risk → goal → requirement → control → claim → test, as typed graph edges. A claim holds only while its evidence holds — break any link and everything upstream demotes itself. No status field anyone can hand-edit to green.
Every risk decision
spawns its chain.
A treatment decision on Sheet 02 creates security goals; goals decompose into requirements. Both stay wired to the risk that caused them — nothing floats free in a requirements tool.
A claim is only as good
as its newest evidence.
Controls implement requirements; claims assert they work. Status is derived from the chain — change a requirement upstream and the claim demotes until re-verified.
Campaigns generated
from attack paths.
Pick an attack path from the TARA — TestBench Agent builds the lab campaign: UDS recon, protocol fuzzing, CANoe execution. Results attach to claims as verification evidence; failures re-open the risks upstream.