Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » ISO 27001 » PDCA Cycle

PDCA Cycle

The Plan-Do-Check-Act (PDCA/PDSA) cycle is a simple and effective approach with a continuous loop of planning, doing, checking (or studying), and acting, and it is generally used for testing improvement measures on a smaller scale before scaling procedures and working practices.

Additional reading

Identity and Access Management for Security and Compliance

TL,DR: IAM ensures the right people access the right resources at the right times through authentication (verifying identity) and authorization (determining access permissions). In 2023, 83% of organizations experienced identity-related data breaches Key technologies include Single Sign-On (SSO) for unified access across applications, Multi-Factor Authentication (MFA) for layered verification, Role-Based Access Control (RBAC) for function-based…

GRC in Cybersecurity: How to Build a Program That Actually Works

TL,DR: Cyber GRC connects security posture to business goals, legal duties, and risk appetite. It defines ownership, risk escalation, control mapping, framework evidence, and board-level reporting. The article covers cybersecurity frameworks, operating models, metrics, AI governance, and a 12-month plan. GRC in cybersecurity is now key to containing rising incident rates. A recent security report…

How to conduct a user access review?

On May 2023, a disgruntled Tesla ex-employee used his privileges as a service technician to gain access to data of 75,735 employees, including personal details and financial information. The breach attracted a $3.3 billion fine under GDPR.  While breaches due to external and unknown factors are not under an organization’s control, such incidents can be…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.