Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » NIST » NIST 800-115

NIST 800-115

NIST Special Publication 800-115, Technical Guide to Information Security Testing and Assessment aims at assisting the organization in discovering the system vulnerabilities through risk assessment and periodic penetration testing. This helps understand the effectiveness of security controls and the flaws that could be exploited by an attacker.

This guide has been divided into some chapters dealing with varied aspects of the security test:

  • Overview of Security Testing and Examination: This introduces basic concepts and principles of security testing.
  • Overview of the Techniques: The methods to analyze controls and configurations are discussed.
  • Target Identification and Analysis: These are techniques to identify target systems and analyze the state of security of the identified systems. The activities include network discovery, vulnerability scanning, and wireless scans.
  • Validation Techniques of Target Vulnerability: These are the processes to validate the existence of an identified vulnerability with impact using penetration testing techniques.
  • Security Assessment Planning: This involves patch management and incident response activities for identified vulnerabilities, ensuring that the software maintains its integrity and security after release.
  • Conducting the Security Assessment: It entails conducting safety and security assessments and detailing exactly how it would be done by making tests and evaluations.
  • Activities Post-Testing: This entails reporting and remediation post-testing

NIST SP 800-115 also accommodates baseline competencies to be used to execute these types of assessments as well as methods of testing.

Additional reading

Breaking Down Malware Statistics: What They Reveal About Cyber Threats Today

TL,DR: Malware trends show attackers using smarter delivery methods, automation, and social engineering. Common risks include ransomware, spyware, trojans, worms, fileless malware, and malicious attachments. Prevention requires endpoint security, patching, monitoring, user training, and incident response preparation. Malware has evolved substantially since its humble beginnings as experimental pranks or minor exploits. Global malware volume rose…

HIPAA vs GDPR (Differences and Similarities)

TL,DR: HIPAA protects PHI in the US healthcare sector; GDPR protects EU personal data across industries. GDPR requires breach notification within 72 hours, while HIPAA timelines depend on breach size. The article compares scope, rights, breach rules, penalties, obligations, and shared privacy goals. HIPAA and GDPR are two of the most stringent privacy and security…

Recovery Point Objective for Costs, Risks, and Resilience

TL,DR: Recovery Point Objective (RPO) is the maximum acceptable data loss measured in time during an unexpected event. It works alongside RTO, which determines how quickly systems must be restored RPO is calculated from 3 factors: data recovery cost, required system performance, and overall risk tolerance. Critical systems require near-zero RPO with continuous replication, while…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.