Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » GDPR » Data Minimization

Data Minimization

Data Minimization represents that a data controller should restrict the collection of personal information to what is directly necessary and relevant to accomplish a certain task and only for a period deemed necessary to fulfil that purpose.

Additional reading

A Guide to Cloud Security Controls and Frameworks

TL;DR Cloud security controls are incomplete without visibility, automation, access management, integrations, and event management. Critical cloud security controls align with governance, risk management, and compliance monitoring functions.  Implementing a cloud security control model with GRC tools includes configuring IAM, automating monitoring, enabling continuous assessments, centralizing incident response, and monitoring metrics.  Cloud security controls are…

How to Implement an Effective Risk Management Process

TL,DR: Risk management process turns uncertain threats into tracked risks with owners and actions. The five steps are risk identification, analysis, mitigation, treatment, and ongoing monitoring. You’ll learn assessment methods, risk registers, response techniques, dashboards, and stakeholder alignment. Risk management should be a key focus for any project. Whether it’s stakeholder misalignment or sudden regulatory…

Access Control List: A Critical Tool for Securing Your Network

TL,DR: An access control list (ACL) is a register defining user permissions that grant or deny access to critical systems and networks. Insiders caused 20% of data breaches in 2022 due to privilege creep (Verizon) Two types exist: standard ACLs (filter by source IP only, applied near destination) and extended ACLs (filter by source IP,…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.