Security Requirements Traceability Matrix (srtm)

Primary definition

Matrix that captures all security requirements linked to potential risks and addresses all applicable C&A requirements. It is, therefore, a correlation statement of a system's security features and compliance methods for each security requirement. (CNSSI-4009) (NISTIR)

Also known asSRTM · Security Traceability Matrix · Requirements Traceability Matrix · Security Compliance Matrix
1 sources cited4 related termsReviewed Aug 10, 2026
The Cyber GlossaryView source
People also ask

What does SRTM mean?

The term Security Requirements Traceability Matrix (SRTM) refers to a matrix linking security requirements to design elements, controls, implementation evidence, and test or verification activities so each requirement can be traced through the system lifecycle. It gives election, security, legal, or technical readers a specific label for the concept rather than a broader everyday meaning.

How is security requirements traceability matrix (SRTM) used in testing or certification?

In practice, Security Requirements Traceability Matrix (SRTM) is applied to the technical or security purpose captured by its definition: a matrix linking security requirements to design elements, controls, implementation evidence. Organizations combine that function with documented procedures, authorized access, testing, monitoring, and controls appropriate to the system. The governing standard or security policy determines the exact implementation.

Why does security requirements traceability matrix (SRTM) matter for assurance?

Understanding Security Requirements Traceability Matrix (SRTM) matters because the concept can affect security, reliability, auditability, or trusted operation. In this glossary context, it refers to a matrix linking security requirements to design elements, controls, implementation evidence. Applying the term precisely helps teams choose controls that match the actual technical function instead of assuming a broader or unrelated meaning.

Understand more election terms clearly

Get one important election term explained each week, with authoritative sources, practical context and related definitions.

Free. One useful email each week. Unsubscribe anytime.Learn more about the ESG newsletter →
TCG

Matrix that captures all security requirements linked to potential risks and addresses all applicable C&A requirements. It is, therefore, a correlation statement of a system's security features and compliance methods for each security requirement. (CNSSI-4009) (NISTIR)

The Cyber Glossary · 2024

Cite this term

Permanent URL · stable across revisions
Election Security Glossary. (2026). Security Requirements Traceability Matrix (srtm). In Election Security Glossary. Retrieved August 21, 2026, from https://electionsecurityglossary.com/glossary/security-requirements-traceability-matrix-srtm

Sources

1 cited · last checked Aug 10, 2026

01

The Cyber Glossary
The Cyber Glossary

Single-source

View source

Get the weekly election term

Receive one cited, source-backed election explanation in your inbox each week.

Get election terms explained weekly →
Free · Nonpartisan · Unsubscribe anytime.
Continue Research

Keep going from here

Three ways to go deeper on cybersecurity and adjacent terminology.