Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » SOC 2 » SSAE 18

SSAE 18

SSAE 18 is a set of updates to the SOC (Service Organization Control) report standards, replacing the previous version, SSAE 16, and the older SAS 70 report. These enhancements aim to improve the quality and usefulness of SOC reports. With these updates, companies will be required to take more responsibility for identifying and categorizing risks and properly managing their relationships with third-party vendors. These changes will help address any gaps identified in the reports of many service organizations, although they are relatively manageable.

Additional reading

ISO 27001:2013 – A Guide to Information Security Management

TL,DR: The legacy ISO 27001 version shaped how organizations built information security management systems. It focused on risk management, policies, controls, audits, and continual improvement. Organizations should understand older requirements when migrating, auditing, or comparing control changes. In response to growing security concerns and breaches, the International Organization for Standardization (ISO) and the International Electrotechnical…

HIPAA Compliance Officer Job Role and Responsibilities

TL,DR: A HIPAA compliance officer develops, implements, and oversees the compliance program with two functions: a Privacy Officer handling PHI policies and breach investigations, and a Security Officer managing technical safeguards and vulnerability assessments HIPAA applies to covered entities (hospitals, providers, health plans), business associates (IT vendors with PHI access), and subcontractors. Ransomware attacks against…

Cyber Risk Quantification: Assessing and Prioritizing Cyber Threats

TL,DR: Cyber risk quantification measures IT risks in financial terms, calculating frequency of occurrence, potential business impact, and disruption to key operations. It replaces guesswork with data-driven prioritization for CISOs and IT teams The U.S. Department of Defense states that threats, vulnerabilities, and impacts must be evaluated together to identify trends and allocate effort toward…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.