Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » ISO 27001 » Residual Risk

Residual Risk

Residual risk is the risk posed to an enterprise after security measures have been put into place.

Additional reading

Integrated Risk Management: A Practical Guide for 2026

TL,DR: Integrated Risk Management (IRM) is a connected approach to managing risk across your entire organization, covering cyber, compliance, operational, and financial risks in one place rather than in separate silos and spreadsheets. It’s built for teams that already do risk management but find it fragmented, manual, and disconnected from their audits. As risks compound…

Vulnerability & Risk Management: Not the Interchangeable Words We Think They Are

TL,DR: Vulnerability management finds and fixes technical weaknesses across systems, applications, and networks. Risk management weighs how those weaknesses affect business objectives, operations, reputation, and finances. The article explains risk-based vulnerability management, prioritization, and budget allocation. When it comes to asset protection, two terms crop up in the boardroom conversation: vulnerability management and risk management….

What is PCI DSS Scope? (How to Create One)

TL,DR: PCI DSS scope covers all processes, people, and technologies that interact with cardholder data (CHD) or impact its security, and every in-scope component must meet all 12 PCI DSS requirements Scope falls into 3 categories: in-scope systems (directly handle CHD), connected-to systems (network access to CDE but no CHD processing), and out-of-scope systems (fully…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.