Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » PCI DSS » Compensating Controls

Compensating Controls

Also referred to as Alternative Controls, it is a set of security and privacy controls implemented by an organization in lieu of the NIST Special Publication 800-53 to mitigate risks and provide an alternative approach to achieving the same security objectives as primary controls. They are often used to reduce the impact of security breaches or data loss when standard controls are not functioning as intended or when you cannot implement primary security controls due to technical or operational limitations. Compensating controls should be appropriately documented and regularly reviewed to ensure their effectiveness.

Additional reading

Access Control List: A Critical Tool for Securing Your Network

TL,DR: An access control list (ACL) is a register defining user permissions that grant or deny access to critical systems and networks. Insiders caused 20% of data breaches in 2022 due to privilege creep (Verizon) Two types exist: standard ACLs (filter by source IP only, applied near destination) and extended ACLs (filter by source IP,…

Compliance Reporting: Types, Reporting Process and Examples

TL;DR Compliance reporting documents how an organization meets external laws, regulations, and internal policies, identifying violations and outlining corrective actions to address deficiencies. The primary goals are to demonstrate legal accountability, improve risk management, and build stakeholder trust with regulators and customers. Several report types exist: regulatory (GDPR, HIPAA), financial (SOX), IT and cybersecurity (ISO…

A Brief Comparison Between PII vs. PHI vs. PCI

TL,DR: PII identifies a person, PHI links identity to health data, and PCI covers cardholder data. Each data type carries different privacy, security, and regulatory protection requirements. The article compares examples, applicable standards, risk exposure, and safeguards for each category. The protection of personal information is becoming critical for businesses worldwide in an increasingly digital…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.