Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
dido:99_annexes:annex-b-terms-and-definitions:c:compliance [2026/07/18 12:33] – external edit 127.0.0.1dido:99_annexes:annex-b-terms-and-definitions:c:compliance [2026/08/06 09:48] (current) nick_dido
Line 7: Line 7:
 Compliance is the condition of satisfying specified legal, regulatory, contractual, policy, standard, control, benchmark, or other applicable criteria. Compliance is the condition of satisfying specified legal, regulatory, contractual, policy, standard, control, benchmark, or other applicable criteria.
  
-compliance determination depends on the defined subject, criteria, scope, operating context, assessment method, evidence, and time of evaluation.+Compliance determination depends on the defined:
  
-Compliance may apply to systemserviceprocessorganizationartifactconfiguration, environment, or individual controlA subject may comply with one set of criteria while failing to comply with another.+  * Subject 
 +  * Applicable criteria 
 +  * Controlling sources 
 +  * Controlling source [[dido:99_annexes:annex-b-terms-and-definitions:v:version|Versions]] 
 +  * Scope 
 +  * Operating context 
 +  * Assessment method 
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] 
 +  * Time of evaluation 
 +  * Applicable [[dido:99_annexes:annex-b-terms-and-definitions:a:authority|Authority]] 
 + 
 +Compliance can apply to
 + 
 +  * A [[dido:99_annexes:annex-b-terms-and-definitions:c:candidate_solution|Candidate Solution]] 
 +  * A [[dido:99_annexes:annex-b-terms-and-definitions:d:distributed_system|Distributed System]] 
 +  * A system 
 +  * A service 
 +  * A process 
 +  * An [[dido:99_annexes:annex-b-terms-and-definitions:o:organization|Organization]] 
 +  * An [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actor]] 
 +  * A [[dido:99_annexes:annex-b-terms-and-definitions:n:node|Node]] 
 +  * A [[dido:99_annexes:annex-b-terms-and-definitions:q:qualified_node|Qualified Node]] 
 +  * A [[dido:99_annexes:annex-b-terms-and-definitions:n:node_set|Node Set]] 
 +  * An artifact 
 +  * A [[dido:99_annexes:annex-b-terms-and-definitions:c:configuration|Configuration]] 
 +  * A [[dido:99_annexes:annex-b-terms-and-definitions:t:test_environment|Test Environment]] 
 +  * An individual control 
 +  * Another subject governed by applicable criteria 
 + 
 +A subject can comply with one set of criteria while failing to comply with another
 + 
 +Applicable criteria can originate from: 
 + 
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:r:requirement|Requirements]] 
 +  * Laws 
 +  * Regulations 
 +  * Contracts 
 +  * Agreements 
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_policy|Governance Policies]] 
 +  * Standards 
 +  * Specifications 
 +  * Controls 
 +  * Benchmarks 
 +  * Decisions of an applicable Authority 
 +  * Other controlling sources 
 + 
 +A Compliance evaluation can result in a determination such as: 
 + 
 +  * Satisfied 
 +  * Not satisfied 
 +  * Partially satisfied 
 +  * Not applicable 
 +  * Not evaluated 
 +  * Inconclusive 
 +  * Another status established by the applicable criteria 
 + 
 +The controlling source, Governance Policy, [[dido:99_annexes:annex-b-terms-and-definitions:v:validation_criteria|Validation Criteria]], or [[dido:99_annexes:annex-b-terms-and-definitions:a:acceptance_criteria|Acceptance Criteria]] establishes the permitted Compliance determinations.
  
 Compliance differs from [[dido:99_annexes:annex-b-terms-and-definitions:a:accreditation|Accreditation]]. Compliance establishes satisfaction of specified criteria, while Accreditation provides formal recognition within a defined scope and operating context. Compliance differs from [[dido:99_annexes:annex-b-terms-and-definitions:a:accreditation|Accreditation]]. Compliance establishes satisfaction of specified criteria, while Accreditation provides formal recognition within a defined scope and operating context.
Line 19: Line 75:
 ===== Source ===== ===== Source =====
  
-Generalized from conformity assessment, governance, risk management, regulatory practice, security engineering, and quality management and specialized for the Crucible architecture and operational model.+Generalized from
 + 
 +  * Conformity assessment 
 +  * Governance 
 +  * Risk management 
 +  * Regulatory practice 
 +  * Security engineering 
 +  * Quality management 
 + 
 +Specialized for
 + 
 +  * Crucible architecture and operations 
 +  * DIDO Reference Architecture 
 +  * DIDO Reference Implementation Conceptual Model 
 +  * DIDO-TE comparative evaluation and Validation 
 + 
 +The original definition and its approved intent are preserved.
  
 ===== Note ===== ===== Note =====
  
-Compliance is not an absolute property without a stated reference. A compliance claim should identify the applicable criteria, version, scope, assessment method, and evaluation time.+Compliance is not an absolute property without a stated reference.
  
-Evidence supports a compliance determination but does not by itself establish that the subject satisfies the applicable criteria.+A Compliance claim should identify: 
 + 
 +  * The subject 
 +  * The applicable criteria 
 +  * The controlling source 
 +  * The controlling source Version 
 +  * The evaluation scope 
 +  * The operating context 
 +  * The assessment method 
 +  * The evaluation time 
 +  * The applicable Authority 
 +  * The supporting Evidence 
 + 
 +Evidence supports a Compliance determination but does not by itself establish that the subject satisfies the applicable criteria. 
 + 
 +Compliance differs from [[dido:99_annexes:annex-b-terms-and-definitions:e:evaluation_characteristic|Evaluation Characteristic]]: 
 + 
 +  * An Evaluation Characteristic identifies a characteristic selected for measurement, observation, comparison, or evaluation 
 +  * Compliance identifies the condition of satisfying applicable criteria 
 + 
 +A comparative evaluation can evaluate the Compliance of multiple Candidate Solutions, but Compliance does not become a Quality Characteristic solely because it participates in the evaluation. 
 + 
 +Compliance differs from [[dido:99_annexes:annex-b-terms-and-definitions:s:security|Security]]: 
 + 
 +  * Compliance concerns satisfaction of applicable criteria 
 +  * Security concerns protection of information, operations, and Resources according to applicable authorization and security constraints 
 + 
 +A subject can satisfy specified security criteria while retaining security risks not addressed by those criteria. 
 + 
 +A subject can implement effective security controls but fail Compliance because it does not satisfy an applicable documentation, authorization, reporting, retention, or Evidence obligation. 
 + 
 +Compliance differs from a [[dido:99_annexes:annex-b-terms-and-definitions:v:verdict|Verdict]]: 
 + 
 +  * Compliance identifies a condition relative to applicable criteria 
 +  * A Verdict records an evaluation assigned to a [[dido:99_annexes:annex-b-terms-and-definitions:t:test_result|Test Result]] 
 + 
 +Multiple Test Results and Verdicts can support one Compliance determination. 
 + 
 +Compliance differs from a [[dido:99_annexes:annex-b-terms-and-definitions:v:validation_decision|Validation Decision]]: 
 + 
 +  * Compliance identifies the condition of satisfying applicable criteria 
 +  * A Validation Decision records a determination produced by evaluating information against Validation Criteria 
 + 
 +A Validation Decision can establish or support the Compliance status of a subject. 
 + 
 +An approved exception, waiver, or deviation does not erase the underlying criterion. The Compliance record should preserve: 
 + 
 +  * The underlying criterion 
 +  * The approved exception, waiver, or deviation 
 +  * The approving Authority 
 +  * The approval period 
 +  * The approval conditions 
 +  * The supporting Evidence 
 +  * The applicable [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] 
 +  * The applicable [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]
  
 ===== Example ===== ===== Example =====
  
-A Hardened Image satisfies the applicable requirements of a selected [[dido:99_annexes:annex-b-terms-and-definitions:s:stig|Security Technical Implementation Guide (STIG)]] profile at the time of assessment. The compliance claim applies to that image, profile, release, assessment method, and recorded configuration.+A Hardened Image satisfies the applicable requirements of a selected [[dido:99_annexes:annex-b-terms-and-definitions:s:stig|Security Technical Implementation Guide (STIG)]] profile at the time of assessment. 
 + 
 +The Compliance claim applies to
 + 
 +  * The identified Hardened Image 
 +  * The selected STIG profile 
 +  * The STIG profile Version 
 +  * The recorded Configuration 
 +  * The assessment scope 
 +  * The assessment method 
 +  * The evaluation time 
 +  * The supporting Evidence 
 + 
 +In a DIDO-TE comparative evaluation, three Candidate Solutions are evaluated against the same regulatory, security, retention, audit, interoperability, and Evidence-preservation criteria. 
 + 
 +[[dido:99_annexes:annex-b-terms-and-definitions:d:dido-te|DIDO-TE]] preserves Traceability among each Candidate Solution, applicable criterion, controlling source, Test Definition, Test Result, Verdict, Compliance determination, and supporting Evidence.
  
 ---- ----
  • dido/99_annexes/annex-b-terms-and-definitions/c/compliance.1784403223.txt.gz
  • Last modified: 2026/07/18 12:33
  • by 127.0.0.1