Compliance Benchmark
Discussion
A Compliance Benchmark is a defined collection of criteria, checks, configuration expectations, assessment procedures, or evaluation rules used to determine Compliance for a specified subject and operating context.
The benchmark may apply to an operating system, application, service, Platform, Machine Image, infrastructure environment, or organizational process.
A Compliance Benchmark may identify individual rules, severity levels, control references, applicability conditions, assessment methods, remediation guidance, and expected evidence.
A Security Technical Implementation Guide (STIG) can serve as a Compliance Benchmark for a defined product or technology. Within Crucible, the selected benchmark forms part of the applicable Compliance Baseline and Compliance Posture.
Definition
defined collection of criteria, checks, configuration expectations, assessment procedures, or evaluation rules used to determine compliance for a specified subject and operating context
Source
Generalized from conformity assessment, cybersecurity, configuration assessment, quality management, and regulatory-compliance usage and specialized for the Crucible architecture and operational model.
Note
A Compliance Benchmark should identify its issuing authority, version, applicable subject, scope, and assessment context.
Applying a Compliance Benchmark does not establish compliance unless the assessment evaluates the applicable criteria and records the resulting findings and evidence.
Example
A Crucible Image Baseline selects a Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux (RHEL) 9 as the Compliance Benchmark for a Hardened Image.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.