Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary Β» NIST Β» NIST CSF Informative References

NIST CSF Informative References

Informative references in NIST CSF are the sources that help to achieve a particular requirement. These sources are mapped to other guidelines, frameworks, or practices that are common among all sectors. 

For example, the Identify function in NIST CSF includes the subcategory that requires users to build an inventory for their physical devices and systems. The informative references for achieving this include the following: 

  • CIS CSC 1Β 
  • COBIT 5 BAI09.01, BAI09.02Β 
  • ISA 62443-2-1:2009 4.2.3.4Β 
  • ISA 62443-3-3:2013 SR 7.8Β 
  • ISO/IEC 27001:2013 A.8.1.1, A.8.1.2Β 
  • NIST SP 800-53 Rev. 4 CM-8, PM-5

Additional reading

Cybersecurity for Small Businesses: Practical Security Strategies

There are several myths and misconceptions surrounding cybersecurity for small businesses. Why would the attackers target small businesses? They aren’t large enough.  Small businesses often do not have big budgets for cybersecurity. But they do have valuable data. So, cybersecurity isn’t just an IT issue. In reality, 48% of small businesses faced an attack by…

Oneleet vs Delve: A Complete Feature-by-Feature Comparison

If you’re researching Oneleet vs Delve, you’re probably close to making a decision on which platform will run your compliance program. Both promise to make compliance easier and audits smoother, but they take very different approaches. Those differences can shape how fast you get certified, how much work your team takes on, and how well…

ISO 9001 Training: Requirements, Types and Costs

TL;DR ISO 9001 training comes in two paths: Internal Auditor (2-3 days, builds in-house audit capability) and Lead Auditor (5 days, qualifies you to lead external and third-party audits). Training covers the seven quality management principles, from customer focus and leadership to evidence-based decision making, giving teams practical tools to fix process gaps and reduce…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.