A security assessment typically reviews access controls, data protection, network and application security, policies, incident response and compliance certifications. It compares that evidence against a control framework to identify gaps and rate the resulting risk. For vendors, it also considers what data and systems they will be able to touch.
