Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » PCI DSS » PCI DSS – Level 4

PCI DSS – Level 4

PCI DSS – Level 4 applies to merchants that process less than 20,000 card transactions per year. At this level, merchants are required to adhere to level 4 grade protocols, and the business should not have encountered cyber attacks that compromised card holder’s data.

Additional reading

Top 4 Data Privacy Frameworks Explained

TL,DR: Data privacy frameworks help organizations manage how personal data is collected, used, stored, shared, retained, and deleted. Key frameworks to evaluate include the NIST Privacy Framework, ISO/IEC 27701, and GDPR, with HIPAA relevant for healthcare organizations handling Protected Health Information (PHI). The right framework depends on geography, data type, industry, customer expectations, and whether…

Writing an Effective ISO 27001 Scope Statement Made Easy

Just like how a building is only as good as its foundation, your ISO 27001 certification is only as good as the scope of your Information Security Management Systems (ISMS). Writing the scope statement, therefore, is undeniably one of the most critical things you will do when you kickstart your ISO 27001 compliance journey. To…

Access Control List: A Critical Tool for Securing Your Network

TL,DR: An access control list (ACL) is a register defining user permissions that grant or deny access to critical systems and networks. Insiders caused 20% of data breaches in 2022 due to privilege creep (Verizon) Two types exist: standard ACLs (filter by source IP only, applied near destination) and extended ACLs (filter by source IP,…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.