Compliance with the requirements defined in this control are a deployer responsibility.
Organizations may reference the available VMware Tanzu Application Service product documentation when developing their security concept of operations.
The organization:
The security CONOPS may be included in the security plan for the information system or in other system development life cycle-related documents, as appropriate. Changes to the CONOPS are reflected in ongoing updates to the security plan, the information security architecture, and other appropriate organizational documents (e.g., security specifications for procurements/acquisitions, system development life cycle documents, and systems/security engineering documents).