Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » NIST » NIST CSF 2.0

NIST CSF 2.0

NIST Cybersecurity Framework (CSF) 2.0 is an update to NIST CSF  framework.  It expands principles of NIST CSF and adds more structured guidance on minimizing cybersecurity risks. It encompasses organizations of all sizes, irrespective of their security maturity.

After the successful debut of the NIST CSF in 2014 and adoption by 50% of US-based organizations just after 6 years of release, NIST started working on NIST CSF 2.0 in 2022. The CSF 2.0 was released in February 2024 to include not just critical infrastructure sectors but also businesses ranging from schools and startups to enterprise and government organizations.

NIST CSF 2.0 also has a lot of informative references for better adoption and supports integration with other risk programs. reflecting the rapidly changing digital landscape and serving as a comprehensive tool for organizations to strengthen their cybersecurity defenses.

Additional reading

Components of HIPAA: Understanding its Rules, Requirements, and Compliance Obligations

TL,DR: HIPAA is built on 5 rules: Privacy Rule (PHI use), Security Rule (ePHI safeguards), Breach Notification Rule (reporting), Transactions and Code Sets Rule (standardized electronic transactions), and Unique Identifiers Rule The Security Rule requires 3 safeguard categories: administrative (risk assessments, training), physical (facility controls, workstation security), and technical (access controls, encryption, audit controls) The…

How Can You Achieve GDPR Compliance in 2026? A Guide for Businesses

TL,DR: GDPR applies to any business processing EU residents’ personal data, regardless of location. Core steps include data mapping, consent, privacy notices, safeguards, DPO review, and breach reporting. The article explains scope, penalties, data transfers, compliance steps, and privacy program ownership. GDPR compliance is vital for organizations operating within the EU. Non-compliance can lead to…

ISO 27001 Controls: A Guide to Implementing Annex A Controls

TL;DR ISO 27001 is the international standard for building an Information Security Management System (ISMS). An ISMS is the set of policies, processes, and technical controls you use to manage information security risk. The current version, ISO/IEC 27001:2022, lists 93 controls in Annex A, and you choose the ones that apply to your organization. This…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.