Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » Generic » APT- Advanced Persistent Threat

APT- Advanced Persistent Threat

An Advanced Persistent Threat (APT) is a highly sophisticated and long-lasting cyberattack strategy. In an APT, intruders infiltrate a network covertly, aiming to steal sensitive data over an extended period while avoiding detection.

Key APT objectives:

  • APT attackers target sensitive data like credit card information, bank accounts, passport details, and more.
  • APTs may seek to disrupt an entire system, including cloud resources, by deleting crucial databases.
  • Attackers may gain control of critical websites, potentially impacting stock markets or vital services like hospitals.
  • APTs aim to access essential systems using stolen user credentials.
  • Attackers seek sensitive or incriminating information via intercepted communications.

GhostNet APT

One notable example of an APT is GhostNet. Discovered in March 2009, GhostNet is considered one of the most sophisticated APTs. While its control infrastructure was largely traced to China, the Chinese government denied involvement. 

GhostNet executed attacks by sending spear-phishing emails with malicious files, leading to Trojan horse infections. Once compromised, the attacker could remotely control the infiltrated system, allowing malware downloads and full system control.

Additional reading

HIPAA Data Retention Requirements: A 2026 Guide with State-Wise Policies

TL,DR: HIPAA requires covered entities to retain compliance documentation for six years under 45 CFR 164.530(j) and 164.316, though medical records themselves fall under state laws that often mandate longer. The six-year rule covers policies, procedures, training logs, risk assessments, BAAs, breach documentation, and patient authorization records, measured from creation or last effective date, whichever…

Types of Security Controls With Examples [How to Implement]

In Dec 2022, OU Health, a hospital in Oklahoma, notified about 3000 patients about a breach of their health data after an employee’s laptop was stolen. Sensitive data like treatments, social security numbers, and insurance details were compromised. The incident highlights the importance of implementing all types of security controls. But what are security controls?…

GDPR Privacy Policy: Ensuring Compliance with EU Data Rules

TL,DR: A GDPR privacy policy explains what personal data you collect, why, and how. It should cover legal basis, retention, third-party sharing, DPO contacts, and data subject rights. The article gives policy requirements, common clauses, enforcement examples, and a downloadable template. Key Points Introduction to GDPR The GDPR privacy policy template or GDPR privacy notice…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.