Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » NIST » NIST Risk Management Framework (RMF)

NIST Risk Management Framework (RMF)

NIST Risk Management Framework (RMF) is a seven-step repeatable process to manage and mitigate risks related to information systems. Developed by the National Institute of Standards and Technology (NIST), the framework was originally developed for federal agencies but has since been adopted by various industries to achieve compliance and manage cybersecurity risks.


The framework integrates security, privacy and cybersecurity supply chain risks into system development lifecycle to enable organizations to take a risk-based approach throughout the control implementation process.

The seven key steps in the NIST RMF include:

  • Prepare aims to enable the organizations to understand their risk profiles and prepare for security risks by assessing data, networks and other infrastructure
  • Categorize focuses on sensitivity of information processes and grouping systems accordingly to understand the impact of potential risks
  • Select aims to choose the right security measures to mitigate the identified risks
  • Implement ensures that the chosen controls are implemented and documented
  • Assess evaluates if the implemented controls are functioning as intended to protect the information systems
  • Authorize aims to promote accountability and ensures that the senior management oversees the implementation and assessment of controls to minimize risks
  • Monitor involves continuous oversight of the risk environment and updating the controls as required

Additional reading

PCI DSS 4.0 Compliance: Everything You Should Know

The Payment Card Industry Data Security Standard (PCI DSS) has undergone a significant update with version 4.0. As a business handling payment card data, understanding these changes is crucial for maintaining compliance and protecting sensitive information. This post delves into the key aspects of PCI DSS 4.0, highlighting: We’ll guide you through the most important…

Top 6 Drata Alternatives & Competitors in 2026

Drata helps organizations become audit-ready quickly, but challenges may arise after onboarding. Customers often find that add-ons increase the total cost, evidence uploads cannot be edited, and teams may need to re-upload documents when changes occur. This guide compares six Drata alternatives, highlighting their advantages in automation, evidence management, reporting, and scalability to help you…

What Is SSAE 18? A Complete Overview of the Standard

Most businesses today rely on the cloud, and it can be challenging to ensure that data – whether it’s payroll information, cloud files, or other sensitive material – remains well-protected and organized.  That’s where the American Institute of Certified Public Accountants (AICPA) comes in with its SOC 1 attestation requirements. Originally codified under forms like…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.