Abstract: Embodiments of the invention provide a system and method of evaluating compliance by components of an IT computer infrastructure with a policy by comparing a recipient component of a service that is identified by a component providing such service, to an identity of a component providing such service that is identified by a component receiving of such service.