This is an old revision of the document!


Compliance

Compliance is the condition of satisfying specified legal, regulatory, contractual, policy, standard, control, benchmark, or other applicable criteria.

A compliance determination depends on the defined subject, criteria, scope, operating context, assessment method, evidence, and time of evaluation.

Compliance may apply to a system, service, process, organization, artefact, configuration, environment, or individual control. A subject may comply with one set of criteria while failing to comply with another.

Compliance differs from Accreditation. Compliance establishes satisfaction of specified criteria, while Accreditation provides formal recognition within a defined scope and operating context.

condition of satisfying specified legal, regulatory, contractual, policy, standard, control, benchmark, or other applicable criteria

Generalized from conformity assessment, governance, risk management, regulatory practice, security engineering, and quality management and specialized for the Crucible architecture and operational model.

Compliance is not an absolute property without a stated reference. A compliance claim should identify the applicable criteria, version, scope, assessment method, and evaluation time.

Evidence supports a compliance determination but does not by itself establish that the subject satisfies the applicable criteria.

A Hardened Image satisfies the applicable requirements of a selected Security Technical Implementation Guide (STIG) profile at the time of assessment. The compliance claim applies to that image, profile, release, assessment method, and recorded configuration.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/99_annexes/annex-b-terms-and-definitions/c/compliance.1783971666.txt.gz
  • Last modified: 2026/07/13 12:41
  • by nick_dido