Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » NIST » NIST CSF Informative References

NIST CSF Informative References

Informative references in NIST CSF are the sources that help to achieve a particular requirement. These sources are mapped to other guidelines, frameworks, or practices that are common among all sectors. 

For example, the Identify function in NIST CSF includes the subcategory that requires users to build an inventory for their physical devices and systems. The informative references for achieving this include the following: 

  • CIS CSC 1 
  • COBIT 5 BAI09.01, BAI09.02 
  • ISA 62443-2-1:2009 4.2.3.4 
  • ISA 62443-3-3:2013 SR 7.8 
  • ISO/IEC 27001:2013 A.8.1.1, A.8.1.2 
  • NIST SP 800-53 Rev. 4 CM-8, PM-5

Additional reading

Security Questionnaire for Startups: How to Ace Them Without Slowing Down Sales

If you’re a founder, RevOps lead, or sales engineer at a startup, you’ve likely hit this wall before—a deal that was previously close to being sealed suddenly cools the moment a security questionnaire lands. Instead of pushing forward, the buyer hits pause. Now you’re scrambling—chasing down screenshots, policies, and half-documented answers while the deal risks…

10 Best Enterprise GRC Software in 2026

TL;DR The best enterprise GRC software in 2026 includes Sprinto, Optro(Auditboard), StandardFusion, LogicManager, LogicGate Risk Cloud, IBM OpenPages, Riskonnect, Diligent One Platform, Onspring, ZenGRC, and MetricStream. Enterprise GRC solutions help you centralize controls, evidence, risks, policies, vendor reviews, audits, obligations, and reporting across teams. The strongest GRC platform is the one your team still uses…

Meta and TikTok DSA Case: When Compliance on Paper Isn’t Enough

Meta and TikTok may face penalties of up to 6% of their global earnings for breaching the EU’s Digital Services Act (DSA), but the real significance lies not in the amount, but in what triggered the penalties. In this instance, the regulator did not penalize legal non-compliance. They punished operational failure: controls that existed on…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.