The independent review and examination of records and activities to assess the adequacy of system controls, ensure compliance with established policies and operational procedures, and recommend necessary changes in controls, policies, or procedures.

Source: CMMC Glossary and Acronyms

