What is a Security Impact Analysis?
A Security Impact Analysis (SIA) describes all changes between specific versions of the system or product and categorises each change as having major or minor security relevance. The SIA summarises the impact of each change on the previous evaluation deliverables, stating which deliverables need to be updated and justifying whether a re-evaluation or maintenance audit is appropriate. The SIA, together with guidance on categorising changes, is described in an appendix to the CTAS Methodology (pdf).