Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » GDPR » Breach Notification

Breach Notification

Breach Notification under the GDPR is the obligation of a controller to report any security incident in which individuals’ personal data have been subject to unauthorized access or disclosure, destruction, or other forms of misuse. 

It helps alert data subjects and regulators of a potential breach and provides them with information about the incident. This can include what occurred, what was impacted, and what is being done to mitigate the effects. 

For example, suppose a 3rd party misuses an organization’s system to access a database containing sensitive financial information on its customers. In that case, that organization must notify authorities within 72 hours of discovering the breach. Failing to do so could result in significant fines and penalties for noncompliance.

Additional reading

ISO 27004 Standard: Key to Evaluating Information Security

TL,DR: ISO 27004 helps measure whether your ISMS controls are working as intended. Good metrics need an owner, source, target, review frequency, threshold, and action path. The article covers ISMS KPIs such as access reviews, vulnerability SLAs, incident response, vendor reviews, and exceptions. Most organizations are aware of the ISO 27001 standard that lists guidelines…

FedRAMP Compliance: Importance and Steps

TL,DR: FedRAMP standardizes security assessment, authorization, and monitoring for cloud services used by federal agencies. Cloud providers need FedRAMP authorization to work with federal data and win government contracts. The article explains authorization paths, NIST-based controls, impact levels, costs, timelines, and framework overlap. FedRAMP is the U.S. government’s program for vetting cloud services. Established in…

Complete Guide on HIPAA Compliance Training Requirements

TL,DR: HIPAA mandates compliance training for all covered entity and business associate employees, regardless of whether they directly access PHI, under both the Privacy Rule and Security Rule training standards The Security Rule outlines 4 addressable specifications: periodic security updates, malware prevention and detection, login monitoring procedures, and password creation and protection procedures Training must…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.