Glossary of Compliance
Compliance Glossary
Our list of curated compliance glossary offers everything you to know about compliance in one place.
Risk Assessment
A systematised procedure that involves identifying the current and potential risks, and analysing the magnitude of each risk to manage the threats accordingly. It helps take better and well-informed decisions.
Additional reading
What Is an Access Review?
TL,DR: Access reviews verify whether employees, groups, and third parties still need assigned permissions. The article explains why stale access creates insider risk, credential misuse, and compliance gaps. You’ll learn review steps, common challenges, and how access certification supports least privilege. November 12, 2021. A former South Georgia Medical Center employee made an unauthorized copy…
CCPA exceptions [Types of Data and Companies]
TL,DR: The CCPA exempts nonprofits, government agencies, and insurance institutions under IIPPA. For-profit businesses must comply only if meeting thresholds for revenue ($25 million+), data volume (100,000+ consumers), or data sale revenue (50%+) Data-level exemptions cover information already governed by federal laws including HIPAA (health data), GLBA (financial data), FCRA (credit data), DPPA (driver records),…
7 Major Risks Of Open-Source Software & Mitigation Strategies
Open source software (OSS) has gained popularity due to its accessibility, rich functionality, cost-effectiveness, and flexibility. These advantages make OSS an attractive choice for many, but it is also considered an inherently riskier option. For example, Gilad David Maayan, Security Today, notes: “Open-source is a bit more chaotic, with contributors adding new features and improving…

Sprinto: Your growth superpower
Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.




![CCPA exceptions [Types of Data and Companies]](https://sprinto.com/wp-content/uploads/2023/11/Featured-11-1-1024x675.jpg)

