A systematic evaluation of an organization's security policies, procedures, and controls to assess compliance and identify weaknesses.