Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » ISO 27001 » Corrective Action

Corrective Action

Corrective actions are methodical steps taken by an organization to close gaps, correct errors, or resolve other problems that have been found within the enterprise’s security program and for which the underlying or root cause has also been identified.

Additional reading

Incident Response Plan vs Disaster Recovery Plan: Key Differences

TL,DR: Incident response plans identify, contain, and resolve security incidents during active events. Disaster recovery plans restore systems, data, and operations after the incident is contained. Together, they support resilience across security, continuity, ISO 27001, and NIST expectations. In the first 30 minutes of a ransomware detonation, two simple questions could decide the outcome: Can…

What is a HIPAA Identifier and How is it Used?

TL,DR: HIPAA identifiers are 18 specific data attributes that can identify an individual, including name, geographic location, dates, phone numbers, SSN, medical record numbers, IP addresses, biometric identifiers, and full-face photographs PHI is created only when any of the 18 identifiers are linked to health information. Direct identifiers (like SSN) identify a person alone, while…

ISO 27001 Change Management Policy: A Complete Guide

TL,DR: An ISO 27001 change management policy controls how system, infrastructure, and process changes are approved. It should cover request intake, risk review, testing, approvals, rollback, and evidence capture. The article explains how controlled changes reduce outages, misconfigurations, and audit exceptions. Among fast-growing tech companies, change is constant — from onboarding new SaaS tools and…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.