Glossary of Compliance
Compliance Glossary
Our list of curated compliance glossary offers everything you to know about compliance in one place.
PCI DSS Rules
PCI DSS rules are global security standards for any organization dealing with cardholder data to reduce security incidents, information theft, and data breaches in the payment industry.
Here are the 12 PCI compliance requirements or rules you need to know:
- Install and maintain a firewall to secure network connections
- Change default passwords and security settings provided by vendors
- Protect stored cardholder data with policies for data disposal
- Encrypt cardholder data when transmitting it over public networks
- Use and keep antivirus software updated
- Develop security systems and processes to address vulnerabilities
- Restrict access to cardholder data based on roles and privileges
- Assign user IDs for computer access and implement authentication measures
- Restrict physical access to cardholder data with monitoring tools
- Track and monitor network and data access, maintaining audit trails
- Regularly test systems and processes, including wireless access points
- Have an information security policy outlining technology usage rules and responsibilities
Additional reading
ISO 27001 Certification: A Complete Guide to Process, Costs, and Benefits in 2026
TL; DR ISO 27001 certification costs $10,000 to $50,000+ in the first year for first-time seekers, driven by organization size, scope, and implementation approach, with surveillance audits in years two and three at $3,000 to $7,500 annually. The process has nine steps: planning, defining ISMS scope, risk assessments, building a security framework, implementing controls, evaluating…
HIPAA vs SOC 2: Key Rules, Scope, and Compliance Steps
TL,DR: HIPAA is a legal requirement for PHI; SOC 2 is a voluntary assurance report. You need HIPAA for health data and SOC 2 when customers ask for control proof. The article compares scope, rules, flexibility, enforcement, security controls, and when teams need both. Your team already has a SOC 2 report in place. For…
SOC Audits : A Complete Rundown of Types, Components & Process
When it comes to protecting your business, a SOC audit is your secret weapon. It’s no longer enough to rely on cloud services and third-party vendors without having airtight security controls. With the rising stakes in data protection, SOC audits have become a vital tool to not only meet compliance but to build trust with…

Sprinto: Your growth superpower
Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.






