Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HIPAA » SRA Tool

SRA Tool

The OCR in partnership with the Office of the National Coordinator for Health Information Technology, developed a downloadable Security Risk Assessment (SRA) Tool that guides users through the security risk assessment process by utilizing a simple, wizard-based approach as asked for by the CMS or the Centers for Medicare and Medicaid Service Electronic Health Record (EHR) Incentive Program and the HIPAA Security Rule. Users are guided through threat and vulnerability assessments, multiple-choice questions, and asset and vendor management.

Additional reading

NIST Asset Management: Setup Process and Benefits

TL,DR: NIST asset management tracks both physical assets (computers, mobile devices, endpoints) and virtual assets (operating systems, applications, data, networks) to answer critical security questions about system vulnerabilities and configurations The setup process involves identifying all network assets, classifying them by criticality and data sensitivity, assigning ownership and accountability, implementing monitoring mechanisms, and establishing patch…

GRC in Cybersecurity: How to Build a Program That Actually Works

TL,DR: Cyber GRC connects security posture to business goals, legal duties, and risk appetite. It defines ownership, risk escalation, control mapping, framework evidence, and board-level reporting. The article covers cybersecurity frameworks, operating models, metrics, AI governance, and a 12-month plan. GRC in cybersecurity is now key to containing rising incident rates. A recent security report…

7 Major Risks Of Open-Source Software & Mitigation Strategies

Open source software (OSS) has gained popularity due to its accessibility, rich functionality, cost-effectiveness, and flexibility. These advantages make OSS an attractive choice for many, but it is also considered an inherently riskier option. For example, Gilad David Maayan, Security Today, notes: “Open-source is a bit more chaotic, with contributors adding new features and improving…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.