Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision | |||
| dido:99_annexes:annex-b-terms-and-definitions:c:compliance [2026/07/18 12:33] – external edit 127.0.0.1 | dido:99_annexes:annex-b-terms-and-definitions:c:compliance [2026/08/06 09:48] (current) – nick_dido | ||
|---|---|---|---|
| Line 7: | Line 7: | ||
| Compliance is the condition of satisfying specified legal, regulatory, contractual, | Compliance is the condition of satisfying specified legal, regulatory, contractual, | ||
| - | A compliance | + | A Compliance |
| - | Compliance | + | * Subject |
| + | * Applicable criteria | ||
| + | * Controlling sources | ||
| + | * Controlling source [[dido: | ||
| + | * Scope | ||
| + | * Operating context | ||
| + | * Assessment method | ||
| + | * [[dido: | ||
| + | * Time of evaluation | ||
| + | * Applicable [[dido: | ||
| + | |||
| + | Compliance | ||
| + | |||
| + | * A [[dido: | ||
| + | * A [[dido: | ||
| + | * A system | ||
| + | * A service | ||
| + | * A process | ||
| + | * An [[dido: | ||
| + | * An [[dido: | ||
| + | * A [[dido: | ||
| + | * A [[dido: | ||
| + | * A [[dido: | ||
| + | * An artifact | ||
| + | * A [[dido: | ||
| + | * A [[dido: | ||
| + | * An individual control | ||
| + | * Another subject governed by applicable criteria | ||
| + | |||
| + | A subject | ||
| + | |||
| + | Applicable criteria can originate from: | ||
| + | |||
| + | * [[dido: | ||
| + | * Laws | ||
| + | * Regulations | ||
| + | * Contracts | ||
| + | * Agreements | ||
| + | * [[dido: | ||
| + | * Standards | ||
| + | * Specifications | ||
| + | * Controls | ||
| + | * Benchmarks | ||
| + | * Decisions of an applicable Authority | ||
| + | * Other controlling sources | ||
| + | |||
| + | A Compliance evaluation can result in a determination such as: | ||
| + | |||
| + | * Satisfied | ||
| + | * Not satisfied | ||
| + | * Partially satisfied | ||
| + | * Not applicable | ||
| + | * Not evaluated | ||
| + | * Inconclusive | ||
| + | * Another status established by the applicable criteria | ||
| + | |||
| + | The controlling source, Governance Policy, [[dido: | ||
| Compliance differs from [[dido: | Compliance differs from [[dido: | ||
| Line 19: | Line 75: | ||
| ===== Source ===== | ===== Source ===== | ||
| - | Generalized from conformity | + | Generalized from: |
| + | |||
| + | * Conformity | ||
| + | * Governance | ||
| + | * Risk management | ||
| + | * Regulatory | ||
| + | * Security | ||
| + | * Quality | ||
| + | |||
| + | Specialized | ||
| + | |||
| + | * Crucible architecture and operations | ||
| + | * DIDO Reference Architecture | ||
| + | * DIDO Reference Implementation Conceptual Model | ||
| + | * DIDO-TE comparative evaluation and Validation | ||
| + | |||
| + | The original definition and its approved intent are preserved. | ||
| ===== Note ===== | ===== Note ===== | ||
| - | Compliance is not an absolute property without a stated reference. A compliance claim should identify the applicable criteria, version, scope, assessment method, and evaluation time. | + | Compliance is not an absolute property without a stated reference. |
| - | Evidence supports a compliance | + | A Compliance claim should identify: |
| + | |||
| + | * The subject | ||
| + | * The applicable criteria | ||
| + | * The controlling source | ||
| + | * The controlling source Version | ||
| + | * The evaluation scope | ||
| + | * The operating context | ||
| + | * The assessment method | ||
| + | * The evaluation time | ||
| + | * The applicable Authority | ||
| + | * The supporting Evidence | ||
| + | |||
| + | Evidence supports a Compliance | ||
| + | |||
| + | Compliance differs from [[dido: | ||
| + | |||
| + | * An Evaluation Characteristic identifies a characteristic selected for measurement, | ||
| + | * Compliance identifies the condition of satisfying applicable criteria | ||
| + | |||
| + | A comparative evaluation can evaluate the Compliance of multiple Candidate Solutions, but Compliance does not become a Quality Characteristic solely because it participates in the evaluation. | ||
| + | |||
| + | Compliance differs from [[dido: | ||
| + | |||
| + | * Compliance concerns satisfaction of applicable criteria | ||
| + | * Security concerns protection of information, | ||
| + | |||
| + | A subject can satisfy specified security criteria while retaining security risks not addressed by those criteria. | ||
| + | |||
| + | A subject can implement effective security controls but fail Compliance because it does not satisfy an applicable documentation, | ||
| + | |||
| + | Compliance differs from a [[dido: | ||
| + | |||
| + | * Compliance identifies a condition relative to applicable criteria | ||
| + | * A Verdict records an evaluation assigned to a [[dido: | ||
| + | |||
| + | Multiple Test Results and Verdicts can support one Compliance determination. | ||
| + | |||
| + | Compliance differs from a [[dido: | ||
| + | |||
| + | * Compliance identifies the condition of satisfying applicable criteria | ||
| + | * A Validation Decision records a determination produced by evaluating information against Validation Criteria | ||
| + | |||
| + | A Validation Decision can establish or support the Compliance status of a subject. | ||
| + | |||
| + | An approved exception, waiver, or deviation does not erase the underlying criterion. The Compliance record should preserve: | ||
| + | |||
| + | * The underlying criterion | ||
| + | * The approved exception, waiver, or deviation | ||
| + | * The approving Authority | ||
| + | * The approval period | ||
| + | * The approval conditions | ||
| + | * The supporting Evidence | ||
| + | * The applicable [[dido: | ||
| + | * The applicable [[dido: | ||
| ===== Example ===== | ===== Example ===== | ||
| - | A Hardened Image satisfies the applicable requirements of a selected [[dido: | + | A Hardened Image satisfies the applicable requirements of a selected [[dido: |
| + | |||
| + | The Compliance | ||
| + | |||
| + | * The identified Hardened Image | ||
| + | * The selected STIG profile | ||
| + | * The STIG profile Version | ||
| + | * The recorded Configuration | ||
| + | * The assessment scope | ||
| + | * The assessment method | ||
| + | * The evaluation time | ||
| + | * The supporting Evidence | ||
| + | |||
| + | In a DIDO-TE comparative evaluation, three Candidate Solutions are evaluated against the same regulatory, security, retention, audit, interoperability, and Evidence-preservation criteria. | ||
| + | |||
| + | [[dido: | ||
| ---- | ---- | ||