Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » PCI DSS » XSS

XSS

Cross-Site Scripting (XSS) is a security vulnerability which allows a cyber threat actor to inject malicious code into a web page viewed by other users to steal their sensitive information or perform unauthorized actions. The attacker exploits the vulnerabilities in the website’s code and then injects scripts that can be executed in the website users’ browsers. The cyber threat actors use XSS attacks to steal login credentials, credit card details, session tokens, and more to perform fraudulent activities.

Additional reading

ISO 27001:2013 vs ISO 27001:2022 | Differences & Transitioning

As of October 31, 2025, ISO/IEC 27001:2013 certifications are officially obsolete. If you’re still operating under the 2013 framework, your certification is now non-compliant — and that means exposure to audit failures, contractual breaches, and reputational risk. The shift to ISO/IEC 27001:2022 isn’t just a routine update. It’s a response to today’s real-world threats: cloud…

ISO 27001 Acceptable Use Policy: Requirements, Template, and Best Practices

Scaling a fast-growing tech company comes with invisible risks. As new people, devices, and apps flood your environment, the chances of misuse, accidental data leaks, or non-compliance skyrocket. Founders and compliance leaders often discover too late that while technical controls are in place, one unclear policy, or worse, no policy at all, can derail an…

Fisma vs FedRAMP Certification – Major Differences and Similarities

For Cloud Service Providers (CSPs) and companies wanting to work with United States Federal Government agencies, getting certified is crucial. However, there needs to be more clarity about which certification to go for. When it comes to working with the government, the main certifications you need to know about are FedRAMP (Federal Risk and Authorization…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.