Compliance review (Replaces "Compliance audit")
SFIA 3: Definition
The independent, third-party assessment of the conformity of any activity, process, deliverable, product or service with the criteria of specified standards, such as BS EN ISO 9000/14000, local standards, best practice, or other documented requirements. May relate to, for example, asset management, network security tools, firewalls and internet security, real-time systems and application design.
Proposed for SFIA 4.0:
The independent assessment of the conformity of any activity, process, deliverable, product or service with the criteria of specified standards, such as ISO 27001, local standards, best practice, or other documented requirements. May relate to, for example, asset management, network security tools, firewalls and internet security, real-time systems and application design.