Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » PCI DSS » PCI DSS Standards

PCI DSS Standards

The PCI Data Security Standard (PCI DSS) safeguards cardholder data and sensitive authentication information when processed, stored, or transmitted. The PCI DSS universe is built of 3 important components. They are:

PCI Data Security Standard (PCI DSS)

This component applies to any company that deals with cardholder data, whether it’s storing, processing, or transmitting it. It covers the technical and operational aspects of systems connecting to cardholder data. If your business handles payment cards in any way, you must comply with PCI DSS to ensure data security.

Payment Application Data Security Standard (PA-DSS)

PA-DSS is mainly for software developers and integrators who create applications that are about cardholder data. It also covers applications you sell, distribute, or license to third parties.

PIN Entry Device Security Requirements (PCI PED) 

PCI PED is mainly for manufacturers who create and manage personal identification number (PIN) entry terminals used in financial transactions. PCI PED specifies these devices’ security requirements and ensures you securely handle PINs.

Additional reading

Building Stronger Defenses: A Practical Guide to Essential 8

TL,DR: The Essential 8 is an Australian Cyber Security Centre (ACSC) framework with 4 maturity levels: Level 0 (no implementation), Level 1 (basic controls for common threats), Level 2 (consistent application reducing exploitable gaps), and Level 3 (fully optimized defenses against sophisticated attacks) The 8 strategies cover application control, patching applications, configuring Microsoft Office macro…

Risk Management Policy – How to Automate the Process

With risks becoming increasingly interconnected, the risk management process involves many moving parts. As risks often share multiple points of intersection, they can quickly escalate into events that could potentially collapse a business. Reacting to a crisis when you’re already in the midst of it is far from ideal. Forward-thinking businesses know how crucial it…

Top Data Governance Tools for Better Data Control

In May 2023, Facebook was fined $1.3 billion by Ireland’s Data Protection Commission for breaching GDPR regulations. Even for a tech giant, it was a significant dent on its reputation and was a precedent for many more congressional hearings to follow. It was a cautionary tale for small businesses to tighten their data governance practices. …

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.