Document metadata
- Status
- Maintained
- Approval
- Approved
- Version
- 1.0
- Classification
- PUBLIC
- Owner
- Lightning IT Documentation Maintainers
- Approver
- Lightning IT Product Owners
- Audience
- product and system owners, security and compliance owners, delivery teams, technical reviewers
- Last reviewed
- Next review
- (Annual)
Assessment model
An assessment is a bounded evaluation of a named target against an agreed scope, control set, check method, and evidence expectation. It does not turn an entire product, organization, or environment into an implicitly assessed object.
Assessment targets
| Target type | Bounded subject | Typical review outcome |
|---|---|---|
| Product | a named product and version | traceable product-quality and security statements |
| System or instance | a specific installation or environment | assessment of the named system within the agreed scope |
| Project or delivery | a defined installation, architecture, or delivery | handover, findings, evidence, and acceptance record |
| Continuous validation | a named target over an agreed recurring review cycle | updated findings and evidence for the defined time span |
These target types can use the same governance and control model. Reuse does not make results interchangeable: a product assessment does not prove the state of a customer instance, and an instance assessment does not automatically apply to every deployment.
Scope contract
Before checks begin, record:
- the target identity and version or assessment period;
- the intended outcome and audience;
- included and excluded components, locations, and lifecycle phases;
- accountable product, system, control, evidence, review, and acceptance roles;
- applicable controls and the authority used to select them;
- check methods, expected evidence, and evaluation criteria;
- known assumptions, dependencies, and limitations; and
- review, handover, retention, and reassessment triggers.
Missing scope is not evidence of broad applicability. An unresolved applicability decision remains visible rather than defaulting to “not applicable” or “implemented.”
Responsibility model
The assessment owner coordinates the bounded evaluation. Control owners define and maintain control intent. Evidence owners provide attributable records under the applicable access and retention rules. Reviewers evaluate the stated relationship between a control, check, and evidence. Only the authorized acceptance role decides whether the agreed deliverable is accepted.
One person may hold more than one role only where the governing policy permits it and records the resulting review arrangement.
Continue with the governance and evidence lifecycle.