Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » NIST » NIST CSF Core Functions

NIST CSF Core Functions

The NIST Cybersecurity Framework (NIST CSF) comprises five core functions – Identify, Protect, Detect, Respond, and Recover. These functions offer guidelines to industries, governments, agencies, and organizations of all sizes, sectors, and maturity to manage their cybersecurity risks effectively. These are further divided into five categories and subcategories. Lets understand each of these: 

Identify (ID): Involves understanding the current risk status of organizational assets like people, facilities, systems, hardware, and software. ID.AM (Asset Management)ID.BE (Business Environment)ID.GV (Governance)ID.RA (Risk Assessment)ID.RM (Risk Management Strategy)
Protect (PR): Aids in securing identified assets by reducing the likelihood and impact of cybersecurity threats while enhancing opportunities. PR.AC (Access Control)PR.AT (Awareness and Training)PR.DS (Data Security)PR.IP (Information Protection Processes and Procedures)PR.MA (Maintenance)PR.PT (Protective Technology)
Detect (DE): Helps teams discover and analyze anomalies and threat indicators that signal an ongoing or previous attack. DE.AE (Anomalies and Events)DE.CM (Security Continuous Monitoring)DE.DP (Detection Processes)
Respond (RS): Supports actions that help mitigate and contain damages caused by a security attack. RS.RP (Response Planning)RS.CO (Communications)RS.AN (Analysis)RS.MI (Mitigation)RS.IM (Improvements)
Recover (RC): Restores operations that have been affected to ensure business recovery and continuity. RC.RP (Recovery Planning)RC.IM (Improvements)RC.CO (Communications)

Additional reading

SOC 2 Readiness Assessment [A Quick Guide]

Any company applying for a compliance audit like SOC 2 needs to have a certain degree of confidence. Getting the entire organization aligned with stringent requirements can take months. Moreover, an endeavor like SOC 2 can be expensive. So it’s important that companies know that their prep work is good enough to get them a…

[Product Update] Introducing Sprinto AI: Building Towards Autonomous Compliance and Risk Intelligence

Compliance has always been about balance. Organizations must navigate between risk and readiness, growth and governance, speed and security. But as companies scale, maintaining that balance becomes increasingly difficult. Compliance frameworks multiply. Risks evolve overnight. Evidence becomes outdated faster than it can be reviewed. Traditional GRC tools and basic automation simply can’t keep up with…

ISO 9001:2015, explained clause-by-clause.

The most-adopted quality management standard in the world, in plain English — plus how to actually implement each clause, avoid common audit findings, and keep your QMS healthy between surveillances.

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.