Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » NIST » NIST 800-172

NIST 800-172

NIST Special Publication 800-172 Enhanced Security Requirements for Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations is an extension of the existing NIST SP 800-171. Current version specifically focus on sensitive but unclassified information dealt by organizations on behalf of the federal government and puts forward additional security requirements and practices pertaining to it.

Main features of NIST 800-172 are:

  1. Additional Requirements for Safety: The book offers better controls that are grouped into 14 categories of controls:
  • Access Control
  • Awareness and Training
  • Audit and Accountability
  • Configuration Management
  • Identification and Authentication
  • Incident Response
  • Maintenance
  • Media Protection
  • Personnel Security
  • Physical Protection
  • Risk Assessment
  • Security Assessment
  • System and Communications Protection
  • System and Information Integrity
  1. Proactive Controls: Under NIST 800-172, proactive control includes threat hunting, encryption as well as continuous monitoring all of which will provide a workaround for future risks.
  2. Implementation Guidance: Publication details customised security requirements based on the varying risk levels of CUI. In that case, it also leaves room for adoption.

NIST SP 800-172 aims at assisting in bolstering the non-federal systems’ cybersecurity posture. In this case, the developed publication applies to sectors of critical infrastructure where preventing unauthorized access and disclosure as well as other advanced persistent threats is crucial.

Additional reading

PCI DSS 4.0 Compliance: Everything You Should Know

TL,DR: PCI DSS 4.0 helps organizations secure payment card data and reduce fraud risk. It covers access control, monitoring, vulnerability management, network security, and testing. Businesses handling cardholder data should map controls, fix gaps, and maintain continuous compliance. The Payment Card Industry Data Security Standard (PCI DSS) has undergone a significant update with version 4.0….

How much does GDPR compliance cost?

TL; DR GDPR compliance costs vary by organization size, data complexity, processing scope, current maturity, and whether you need consultants, legal support, security tooling, training, audits, monitoring, or a voluntary certification mechanism. GDPR implementation and maintenance costs range from roughly $20,500 to $102,500+, with major cost categories including implementation and consulting fees, security tools, employee…

What is Consensus Assessments Initiative Questionnaire (CAIQ)? 

TL,DR: The CAIQ is a Cloud Security Alliance tool evaluating cloud provider security capabilities, aligned with the CSA Cloud Controls Matrix (CCM) covering 197 control objectives across 16 domains Toyota’s 2023 exposure of 260,000 customer records from a cloud misconfiguration illustrates why organizations must assess providers before deployment. CAIQ Lite offers a condensed 71-question version…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.