Matrix that captures all security requirements linked to potential risks and addresses all applicable C&A requirements. It is, therefore, a correlation statement of a system's security features and compliance methods for each security requirement. (CNSSI-4009) (NISTIR)
What does SRTM mean?
The term Security Requirements Traceability Matrix (SRTM) refers to a matrix linking security requirements to design elements, controls, implementation evidence, and test or verification activities so each requirement can be traced through the system lifecycle. It gives election, security, legal, or technical readers a specific label for the concept rather than a broader everyday meaning.
How is security requirements traceability matrix (SRTM) used in testing or certification?
In practice, Security Requirements Traceability Matrix (SRTM) is applied to the technical or security purpose captured by its definition: a matrix linking security requirements to design elements, controls, implementation evidence. Organizations combine that function with documented procedures, authorized access, testing, monitoring, and controls appropriate to the system. The governing standard or security policy determines the exact implementation.
Why does security requirements traceability matrix (SRTM) matter for assurance?
Understanding Security Requirements Traceability Matrix (SRTM) matters because the concept can affect security, reliability, auditability, or trusted operation. In this glossary context, it refers to a matrix linking security requirements to design elements, controls, implementation evidence. Applying the term precisely helps teams choose controls that match the actual technical function instead of assuming a broader or unrelated meaning.
Understand more election terms clearly
Get one important election term explained each week, with authoritative sources, practical context and related definitions.
Matrix that captures all security requirements linked to potential risks and addresses all applicable C&A requirements. It is, therefore, a correlation statement of a system's security features and compliance methods for each security requirement. (CNSSI-4009) (NISTIR)
Cite this term
Election Security Glossary. (2026). Security Requirements Traceability Matrix (srtm). In Election Security Glossary. Retrieved August 21, 2026, from https://electionsecurityglossary.com/glossary/security-requirements-traceability-matrix-srtm
Sources
01
Single-source
Get the weekly election term
Receive one cited, source-backed election explanation in your inbox each week.