Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HiTRUST » HITRUST CSF Control Categories

HITRUST CSF Control Categories

HITRUST CSF Control Categories are a bit complex, with over 150 individual controls in total. The exact number of controls your company needs to focus on can vary depending on how you define “control” and your specific compliance needs.

HITRUST organizes its framework into 14 distinct Control Categories, each labeled with a unique identifier from 0.0 to 0.13. These are further organized into 49 objectives and then detailed through 156 references. However, the actual controls your company needs to implement depend on the specifications that apply to your business and other compliance requirements.

The various tiers can get complicated, but the key is to focus on the controls relevant to your organization’s security and compliance needs. Here is the list of controls for your reference.

Control NameControl ObjectivesControl Specifications
Information Security Management Program11
Access Control725
Human Resources Security49
Risk Management14
Security Policy12
Organization of Information Security211
Compliance310
Asset Management25
Physical and Environmental Security213
Communications and Operations Management1032
Information Systems Acquisition, Development, and Maintenance613
Information Security Incident Management25
Business Continuity Management15
Privacy Practices721

Additional reading

Article 28 of GDPR: The Essentials for Data Processors

TL,DR: GDPR Article 28 establishes the Data Processing Agreement (DPA) between controllers and processors, defining the legally binding boundaries and obligations for all personal data handling activities Controllers must only work with processors producing evidence of sufficient technical and organizational safeguards under Article 32. Processors must follow all written instructions and obtain prior authorization before…

10 Best Healthcare Compliance Software in 2026

TL;DR Healthcare compliance software helps you stay continuously audit-ready by centralizing risk assessments, policies, safeguards, vendor oversight (BAAs), and evidence, so you’re not rebuilding proof during HIPAA audits or customer due diligence. The best tools in 2026 fall into three buckets:1. Automation-first GRC for healthtech/security controls (continuous monitoring, evidence, readiness)2. Clinical workforce + credentialing compliance (training, licensing, exclusions)3….

Sprinto Vs Hyperproof: Which GRC Tool Should You Choose?

TL;DR Sprinto and Hyperproof are both GRC platforms that automate compliance, risk management, and audit workflows, but they target different organizational needs. Sprinto is built for cloud-first teams that want controls, evidence, and risk workflows to stay connected without adding enterprise-grade overhead. Hyperproof is built for large enterprises with complex, multi-framework compliance programs, offering extensive…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.