The process of validating the effective implementation of security controls for information systems and networks, based on the organization’s security requirements.
Source(s):
NIST SP 800-115