Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » Generic » Cybersecurity – Shared Responsibility

Cybersecurity – Shared Responsibility

The cybersecurity shared responsibility model plays a great role in mitigating the various aspects of the cloud environment. 

For example, in a shared security model with GCP, Google will be responsible for ensuring that their firewalls remain impenetrable, and you, as a google cloud user, will be responsible for ensuring that you have implemented MFA, used a strong password, and don’t access your business environment that’s hosted on  GCP from open public networks. Google is responsible for guarding the cloud service, while you are responsible for guarding your own account in the cloud service.

Moreover, cybersecurity is a responsibility we all share, and each person plays a role in protecting themselves and others. Just one infected computer can spread malware to countless others. To enhance your safety online, you’ve got to follow some basic cybersecurity measures.

Best practices to ensure your online safety

  • Avoid opening suspicious-looking emails or attachments.
  • Create strong passwords and avoid sharing them with anyone.
  • Keep your operating system, browser, and critical software updated by installing updates regularly.
  • Be cautious about sharing personal information online, and use privacy settings to control the information you share.

Additional reading

7 Best NIST Compliance Software

TL; DR This article reviews the best NIST compliance software to help organizations implement and maintain NIST-aligned security controls, evaluating tools based on automation, continuous monitoring, risk assessment, evidence collection, and audit readiness. Best NIST Compliance Software in 2026:1. Sprinto2. AuditBoard3. Hyperproof4. Netwrix Auditor5. Drata6. RiskOptics (Reciprocity)7. OneTrust NIST isn’t your typical regulatory framework. Companies…

What Is an Access Review?

TL,DR: Access reviews verify whether employees, groups, and third parties still need assigned permissions. The article explains why stale access creates insider risk, credential misuse, and compliance gaps. You’ll learn review steps, common challenges, and how access certification supports least privilege. November 12, 2021. A former South Georgia Medical Center employee made an unauthorized copy…

ISO 27001 Change Management Policy: A Complete Guide

TL,DR: An ISO 27001 change management policy controls how system, infrastructure, and process changes are approved. It should cover request intake, risk review, testing, approvals, rollback, and evidence capture. The article explains how controlled changes reduce outages, misconfigurations, and audit exceptions. Among fast-growing tech companies, change is constant — from onboarding new SaaS tools and…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.