Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » NIST » NIST 800-115

NIST 800-115

NIST Special Publication 800-115, Technical Guide to Information Security Testing and Assessment aims at assisting the organization in discovering the system vulnerabilities through risk assessment and periodic penetration testing. This helps understand the effectiveness of security controls and the flaws that could be exploited by an attacker.

This guide has been divided into some chapters dealing with varied aspects of the security test:

  • Overview of Security Testing and Examination: This introduces basic concepts and principles of security testing.
  • Overview of the Techniques: The methods to analyze controls and configurations are discussed.
  • Target Identification and Analysis: These are techniques to identify target systems and analyze the state of security of the identified systems. The activities include network discovery, vulnerability scanning, and wireless scans.
  • Validation Techniques of Target Vulnerability: These are the processes to validate the existence of an identified vulnerability with impact using penetration testing techniques.
  • Security Assessment Planning: This involves patch management and incident response activities for identified vulnerabilities, ensuring that the software maintains its integrity and security after release.
  • Conducting the Security Assessment: It entails conducting safety and security assessments and detailing exactly how it would be done by making tests and evaluations.
  • Activities Post-Testing: This entails reporting and remediation post-testing

NIST SP 800-115 also accommodates baseline competencies to be used to execute these types of assessments as well as methods of testing.

Additional reading

HIPAA Authorization: Ensuring Patient Privacy and Consent

TL,DR: HIPAA authorization is written patient permission for using or disclosing PHI beyond standard purposes. It is required for psychotherapy notes, marketing, PHI sales, and non-routine disclosures. The article covers authorization elements, exceptions, penalties, and how it supports patient privacy. HIPAA authorization is an important part of safeguarding sensitive patient health information. It is necessary…

Risk Assessment Methodologies Explained [And How to Choose the Right One]

TL,DR: Risk assessment methodologies help teams identify, measure, and prioritize cybersecurity risks. Different methods support qualitative, quantitative, framework-based, and scenario-based analysis. Choosing the right methodology improves risk visibility, control selection, and executive decisions. Businesses in the post-COVID era have realized the need to prioritize the security of their critical assets. In 2023 alone, the average…

FISMA Certification: A Complete Step-By-Step Guide

In 2022, the U.S government introduced FISMA as a part of the E-Government Act. Aimed at protecting information security in the interest of national and economic growth, it explicitly focuses on “risk-based policy for cost-effective security”. If this act applies to your business, understanding the intricacies of the compliance process is essential.  In this article,…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.