Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » NIST » NIST 800-145

NIST 800-145

NIST Special Publication 800-145, titled The NIST Definition of Cloud Computing, provides standardized terminology for cloud computing to ensure uniformity across organizations and industries. It outlines the key characteristics, deployment models, and service models associated with cloud computing to enhance understanding and cloud adoption.

NIST 800-145 outlines five essential characteristics of cloud computing: on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service.

  1. On-demand self-service: This means that users can allocate cloud resources on demand without manual intervention
  2. Broad network access: It indicates that cloud services can be accessed from a wide range of devices using standard methods such as browsers.
  3. Resource pooling: This indicates that cloud computing resources are pooled to provide service to multiple customers
  4. Rapid elasticity: This means that cloud capabilities can be scaled up and down based on requirements
  5. Measured service: It indicates that the usage of cloud resources is monitored and reported

Three Service models: Cloud service models include Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS).Four deployment models: The deployment models are categorized as public cloud, private cloud, hybrid cloud and community cloud.

Additional reading

Security Vs Compliance: Key Differences and Similarities

TL,DR: Security refers to the technical controls protecting assets against cyber threats, while compliance is adherence to third-party regulatory standards demonstrating data protection to external parties Being compliant does not guarantee being secure. An organization can pass an audit while still having exploitable vulnerabilities. Conversely, strong security controls do not automatically satisfy every framework requirement…

Why HIPAA Is Important for Patients and Healthcare

TL,DR: HIPAA is important because it protects patient privacy, giving individuals control over their medical records and holding healthcare organizations legally accountable for safeguarding sensitive health data. HIPAA grants patients critical rights, including accessing their data, correcting their medical records, and filing complaints if information is misused or shared without consent. Covered entities must secure…

HIPAA Enforcement Rule: All You Need To Know In 2026

TL,DR: The HIPAA Enforcement Rule authorizes HHS to investigate and impose civil penalties for ePHI violations across a 4-tier structure: lack of awareness ($100 to $50,000), reasonable cause ($1,000 to $50,000), willful neglect with correction ($10,000 to $50,000), and willful neglect without correction ($50,000 per violation) Annual caps reach $1.5 million per category. The OCR…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.