Compliance Assessment
Discussion
A Compliance Assessment evaluates a subject against identified compliance criteria to determine whether it satisfies them.
The assessed subject may include:
-
An Artifact
-
A service
-
A software component
-
A deployment
-
An operational process
Compliance criteria may derive from:
-
Laws
-
Regulations
-
Standards
-
Policies
-
Contracts
-
Requirements
-
Applicable Acceptance Criteria
A Compliance Assessment may perform activities such as:
-
Identifying the applicable compliance criteria
-
Collecting information about the assessed subject
-
Comparing observed characteristics with the applicable criteria
-
Evaluating collected Evidence
-
Recording satisfied criteria
-
Recording unsatisfied criteria
-
Producing Compliance Findings
-
Recording the assessment result
A Compliance Assessment differs from a Compliance Finding:
-
A Compliance Assessment is the evaluation activity
-
A Compliance Finding is a recorded result produced by that activity
A Compliance Assessment may produce no findings, one finding, or multiple findings.
Definition
assessment that evaluates a subject against identified compliance criteria to determine the extent to which the subject satisfies those criteria
Source
Dido Solutions, Inc. and Jackrabbit Consulting, Inc.
Note
A Compliance Assessment should identify:
-
The assessed subject
-
The applicable compliance criteria
-
The assessment scope
-
The assessment method
-
The observed characteristics
-
The evaluated Evidence
-
The assessment results
-
The resulting Compliance Findings
A Compliance Assessment may be:
-
Automated
-
Manual
-
Partially automated
-
Continuous
-
Periodic
-
Event-triggered
Completion of a Compliance Assessment does not by itself establish authorization, certification, approval, or acceptance. Applicable governance processes determine those outcomes.
The term does not require a particular compliance framework, assessment tool, evidence format, reporting format, or implementation technology.
Example
A Compliance Assessment compares the configuration and observed state of a Red Hat Enterprise Linux Machine Image with an applicable Security Baseline and records a Compliance Finding for each unsatisfied security criterion.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.