Resources / 07

Working definitions for the terms SecondMark uses when discussing claims, evidence, boundaries, controls, opinions, and validity.

Independent software assuranceSM / 07.48

SecondMark position

Shared language prevents important differences—such as testing versus qualification or finding versus opinion—from disappearing inside familiar but ambiguous words.

The examination is bounded to defined claims, a versioned system, and evidence that can be traced to the state under review. Any material exclusion or uncertainty remains visible in the conclusion.

01

Core questions

What the examination needs to establish.

  1. 01

    What is the object of assurance?

  2. 02

    How does a claim differ from a requirement?

  3. 03

    When is evidence sufficient?

  4. 04

    What makes a limitation material?

02

Evidence model

Evidence is assembled around the claim—not the folder structure.

01

System and ownership records

Collected, attributed, challenged, and connected to the exact system boundary under examination.

02

Architecture, control, and runtime material

Collected, attributed, challenged, and connected to the exact system boundary under examination.

03

Known incidents and limitations

Collected, attributed, challenged, and connected to the exact system boundary under examination.

04

Decision context and required claims

Collected, attributed, challenged, and connected to the exact system boundary under examination.

Intended outcome

A common vocabulary for technical teams, executives, and governance stakeholders participating in an engagement.

Clearer engagement preparationReduced evidence ambiguityFaster scope formation
03

Professional boundary

What an opinion does—and does not—mean.

It provides

A traceable independent conclusion on defined claims, grounded in the evidence and system state examined.

It does not provide

A guarantee that failure is impossible, a permanent certification, or a conclusion beyond the stated scope and validity conditions.