Glosario de Cumplimiento

Cumplimiento Glosario

Nuestro glosario de cumplimiento normativo, cuidadosamente seleccionado, ofrece todo lo que necesitas saber sobre cumplimiento en un solo lugar.

Glosario » NIST » Marco de ciberseguridad del NIST (CSF)

Marco de ciberseguridad del NIST (CSF)

The NIST Cybersecurity Framework (CSF) is a set of best practices that organizations can use to safeguard their data and enhance cyber security. Developed by the National Institute of Standards and Technology (NIST), the framework helps organizations protect critical infrastructure, such as healthcare and manufacturers. 

NIST CSF is flexible, adaptable and widely used to benchmark cybersecurity practices. The framework is built around five core functions: Identify, Protect, Detect, Respond, and Recover. These functions guide the organization’s efforts to strengthen their defenses, improve incident response and ensure resilience in the face of evolving threat landscape.

  • Identify: It involves developing an understanding of the organization’s environment to manage risks
  • Protect: It focuses on implementing protective measures to safeguard the delivery of critical services
  • Detect: It aims to identify the occurrence of cybersecurity events in a timely manner through monitoring and detection processes
  • Respond: It involves developing and implementing an action plan when a cybersecurity event occurs to minimize the spread and impact
  • Recover: It focuses on implementing measures to restore the services impacted by an incident as quickly as possible to ensure business continuity. 

Lecturas adicionales

Quantum computing & Post-quantum Cryptography: GRC’s Y2K Moment?

Imagine a world where your personal messages, health records, banking transactions, and confidential information are exposed in seconds because someone could break the encryption methods you trust. A decade ago, this would have seemed like a sci-fi plot, but today, it has the potential to become a very real possibility. As we look toward 2025,…

Outsource Compliance: Streamlining Regulatory Management

TL,DR: 38% of companies already outsource parts of their compliance to stay audit-ready without sacrificing focus on growth. Outsourcing companies monitor regulatory updates, conduct risk assessments, and implement changes proactively Benefits include access to specialized expertise, reduced internal resource burden, scalable solutions that adapt to organizational size, faster time to certification, and lower overall compliance…

¿Qué es la prevención de pérdida de datos (DLP)?

TL,DR: Data loss prevention helps stop sensitive information from being leaked, misused, or exposed. DLP controls monitor data across endpoints, email, cloud apps, and networks. Strong DLP programs use classification, policies, encryption, access control, and alerts. In 2017, Equifax, one of the largest credit reporting agencies in the US, reported a Data breach. The breach…

Sprinto: Tu superpoder de crecimiento

Utilice Sprinto para centralizar la gestión del cumplimiento de la seguridad, de modo que nada
Se interpone en tu camino para ascender y lograr grandes victorias.