Assessment

(1) the process of determining whether an outcome meets the actor’s intent; or (2) an atomic process within an Evaluation used to determine a resource’s Compliance with an Assessment Requirement.

Source: Gemara

Industry Cross-Reference

An assessment is the testing and/or evaluation of the management, operational, and technical security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.

Source: NIST CSRC Glossary - Assessment

Last modified July 23, 2026: chore: add gemara citations (4d1269b)