Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HiTRUST » HITRUST CSF Control Categories

HITRUST CSF Control Categories

HITRUST CSF Control Categories are a bit complex, with over 150 individual controls in total. The exact number of controls your company needs to focus on can vary depending on how you define “control” and your specific compliance needs.

HITRUST organizes its framework into 14 distinct Control Categories, each labeled with a unique identifier from 0.0 to 0.13. These are further organized into 49 objectives and then detailed through 156 references. However, the actual controls your company needs to implement depend on the specifications that apply to your business and other compliance requirements.

The various tiers can get complicated, but the key is to focus on the controls relevant to your organization’s security and compliance needs. Here is the list of controls for your reference.

Control NameControl ObjectivesControl Specifications
Information Security Management Program11
Access Control725
Human Resources Security49
Risk Management14
Security Policy12
Organization of Information Security211
Compliance310
Asset Management25
Physical and Environmental Security213
Communications and Operations Management1032
Information Systems Acquisition, Development, and Maintenance613
Information Security Incident Management25
Business Continuity Management15
Privacy Practices721

Additional reading

May 2026 Product Updates: Smarter AI Capabilities, Structured Privacy Assessments, and More Flexible Governance

Privacy impact assessments still run across email threads and shared documents with no single record of approvals, risk mappings, or assessment outcomes. AI-assisted control mapping only draws from controls your organization has already enabled, leaving coverage gaps that your full control library could fill. Failing monitors get fixed one at a time, each requiring its…

Cyber Security Metrics & KPIs: A Detailed Guide

TL,DR: Cybersecurity metrics help CISOs explain risk, budget needs, and program performance with data. The article covers 22 metrics across threats, vulnerabilities, incidents, compliance, and training. Use them to report security value in terms leadership can understand and compare. As a seasoned security professional, you understand the struggles of convincing the board to approve an…

PCI Compliance for SaaS: A Strategic Guide to PCI DSS Compliance for SaaS Businesses

If you’re a founder, IT, or compliance leader in SaaS, you’ve likely faced the same dreaded moment: an enterprise prospect hits pause because you’re not PCI compliant yet. And suddenly, you’re knee-deep in checklists, unsure where SaaS fits into a retail-centric framework designed two decades ago. PCI is still absolutely critical for safeguarding payment data…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.