Glossary of Compliance
Compliance Glossary
Our list of curated compliance glossary offers everything you to know about compliance in one place.
PCI DSS Rules
PCI DSS rules are global security standards for any organization dealing with cardholder data to reduce security incidents, information theft, and data breaches in the payment industry.
Here are the 12 PCI compliance requirements or rules you need to know:
- Install and maintain a firewall to secure network connections
- Change default passwords and security settings provided by vendors
- Protect stored cardholder data with policies for data disposal
- Encrypt cardholder data when transmitting it over public networks
- Use and keep antivirus software updated
- Develop security systems and processes to address vulnerabilities
- Restrict access to cardholder data based on roles and privileges
- Assign user IDs for computer access and implement authentication measures
- Restrict physical access to cardholder data with monitoring tools
- Track and monitor network and data access, maintaining audit trails
- Regularly test systems and processes, including wireless access points
- Have an information security policy outlining technology usage rules and responsibilities
Additional reading
How to Conduct a Data Protection Impact Assessment (DPIA)?
TL,DR: DPIA helps identify privacy risks before processing personal data under GDPR Article 35. Run it for high-risk processing, including profiling, children’s data, biometrics, location tracking, or automated decisions. The article explains scoping, stakeholder input, risk evaluation, mitigation planning, and final DPIA reporting. Introduction Data Protection Impact Assessment (DPIA) is a part of the EU’s…
Types of Security Controls With Examples [How to Implement]
In Dec 2022, OU Health, a hospital in Oklahoma, notified about 3000 patients about a breach of their health data after an employee’s laptop was stolen. Sensitive data like treatments, social security numbers, and insurance details were compromised. The incident highlights the importance of implementing all types of security controls. But what are security controls?…
HIPAA Security Rule Update 2025: Everything you need to know
When HIPAA was first introduced and even when it received a major overhaul in 2013, the cyber threat landscape was starkly different from what we face today. As a consequence, earlier, HIPAA focused on protecting patients’ privacy during digital transformation and cloud data backup, but it did not mainly ensure security. In 2025, cyber threats…

Sprinto: Your growth superpower
Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.






