Glossary of Compliance
Compliance Glossary
Our list of curated compliance glossary offers everything you to know about compliance in one place.
PCI DSS Rules
PCI DSS rules are global security standards for any organization dealing with cardholder data to reduce security incidents, information theft, and data breaches in the payment industry.
Here are the 12 PCI compliance requirements or rules you need to know:
- Install and maintain a firewall to secure network connections
- Change default passwords and security settings provided by vendors
- Protect stored cardholder data with policies for data disposal
- Encrypt cardholder data when transmitting it over public networks
- Use and keep antivirus software updated
- Develop security systems and processes to address vulnerabilities
- Restrict access to cardholder data based on roles and privileges
- Assign user IDs for computer access and implement authentication measures
- Restrict physical access to cardholder data with monitoring tools
- Track and monitor network and data access, maintaining audit trails
- Regularly test systems and processes, including wireless access points
- Have an information security policy outlining technology usage rules and responsibilities
Additional reading
The AI tool your team approved is now making decisions
And you don’t have visibility into which ones. We spoke to GitHub’s TPRM lead about this and other TPRM risks
11 Best Enterprise Risk Management Platforms for 2026
TL,DR: The guide compares 11 enterprise risk management platforms by workflow fit, integrations, reporting depth, framework support, and scalability. Sprinto suits compliance automation, AuditBoard fits audit-heavy teams, and LogicGate supports highly configurable risk workflows. Choose based on program maturity, risk drivers, live integrations, user adoption, and room to scale. Risk used to be manageable by…
What Is Autonomous Trust?
At the most fundamental level, everything in GRC comes down to a single question behind every business relationship: Can I trust you? Before compliance frameworks, audit cycles, or evidence repositories existed, organizations had to answer that question to function. They had to demonstrate that vendors were vetted, access was managed, and responsibilities were clearly assigned….

Sprinto: Your growth superpower
Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.






