Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » PCI DSS » Card Skimmer

Card Skimmer

Card skimmer is a device attached to the card reader that skims and steals the card information like card number, expiration date, and CVV code. This device reads the debit/credit card information from the magnetic stripe at the back of the card and stores it in its memory module. Generally, a card skimmer is placed in ATMs, shopping malls, petrol pumps, or other Point of Sales (POS) terminals to steal the card information of shoppers. Cybercriminals use this information for unauthorized purchases or to create counterfeit cards.

Additional reading

IT GRC Tools: Complete Guide to Governance, Risk, and Compliance

Most businesses end up adopting IT GRC tools after they’ve seen what happens without it. Every new vendor integration, every new cloud deployment, exposes you to new risks and vulnerabilities.  The old way of managing risk is built for a slower world. At first, it’s manageable, with a few spreadsheets here and a few docs…

Information Security Policy – Everything You Should Know

TL,DR: An information security policy lays the foundation for protecting an organization’s data assets by defining procedures, techniques, and technology for safeguarding confidentiality, integrity, and availability ISO 27001 requires the policy to have management buy-in and mandates that it be shared with all staff. Annex 5 of the standard sets the objectives and must-haves for…

Understanding RBAC: The Key to Effective Role-Based Access Control

A survey conducted by Ponemon Institute on the cost of insider threats found that 56% of incidents are caused by employee negligence. The report also showed that business downtime and revenue loss were the most significant consequence of an insider incident. On average, an incident sets orgs back by $648,062. This number has significantly increased…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.