Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » PCI DSS » CSRF

CSRF

Cross-Site Request Forgery (CSRF) is a security vulnerability that allows a cyber threat actor to perform actions on behalf of the user without their knowledge or consent. The CSRF attack occurs when the user clicks on a malicious link or visits a malicious website. This action makes the user’s browser send requests to legitimate websites where the user is logged in. These requests are generally actions such as deleting data, making purchases, changing passwords, sending messages, and so on. As the request comes from the user’s browser, it is considered legitimate, allowing the cybercriminals to perform unauthorized actions.

Additional reading

[Product Update] Introducing AI-Powered Risk Management

Risk management today feels like chasing a moving target. Threats evolve by the hour. Vendors introduce new exposures with every integration, and evidence that appeared solid last quarter can become outdated before the next audit even begins. Yet most compliance teams are still working reactively, identifying risks only after they’ve caused an audit finding or…

8 Types of Vendor Risks to Identify, Monitor, and Mitigate

TL,DR: Vendor risks include operational, financial, cybersecurity, compliance, reputational, strategic, concentration, and geopolitical exposure. Knowing the risk type helps prioritize controls before vendor issues disrupt business operations. The guide explains practical examples, monitoring methods, and mitigation steps for third-party risk programs. In 2025, over 35% of organizations reported disruptions caused by third-party vendors. The third-party vendor risk…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.