Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » ISO 27001 » Control Objective

Control Objective

The basic goal of access control in the CIA triad is to preserve and secure the confidentiality, integrity, and accessibility of systems, information, and resources.

Additional reading

Vulnerability Management: Key Stages, Challenges, and Best Practices

TL,DR: Vulnerability management identifies, prioritizes, remediates, and tracks security weaknesses across systems. It helps teams focus on the most critical risks instead of treating all vulnerabilities equally. Continuous scanning, patching, asset visibility, and reporting improve security posture. Equifax breach in 2017: attackers exploited a known but unpatched Apache Struts vulnerability, ultimately exposing the personal data…

GDPR for Dummies: Simple GDPR Guide for Beginners

TL;DR GDPR (General Data Protection Regulation) is an EU law that governs how businesses collect, process, store, and protect personal data of individuals. It applies to any organization handling EU residents’ data, regardless of where the business is located. GDPR gives individuals rights over their data (access, deletion, consent, portability) and requires businesses to ensure…

CCPA Privacy Policy: What is it + Sample Template

TL,DR: A CCPA privacy policy outlines how a business collects, uses, shares, and protects California residents’ personal information, required for businesses with $25 million+ revenue, 100,000+ consumer data, or 50%+ revenue from selling data A compliant policy must include data categories collected, collection purposes, consumer rights (access, deletion, opt-out), a “Do Not Sell” link, and…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.