Glossary of Compliance
Compliance Glossary
Our list of curated compliance glossary offers everything you to know about compliance in one place.
Statement of Applicability
A Statement of Applicability is a document needed for ISO 27001 certification. It’s a document that declares the Annex A controls that your enterprise determined to be necessary for mitigating information security risk, including the Annex A controls that were excluded.
Additional reading
A Quick Walk-Through of NIST CSF Maturity Levels and Models
TL,DR: NIST CSF maturity levels show how prepared an organization is to manage cybersecurity risk. The four levels are Partial, Risk-Informed, Repeatable, and Adaptive. The article explains maturity assessment, implementation tiers, posture improvement, and risk-based security planning. Former U.S. Deputy Attorney General Paul McNulty once said, “If you think compliance is expensive, try non-compliance.” And…
Cybersecurity Incident Response Plan: What It Is & How to Build One
The significance of cybersecurity is growing. The world now depends on technology more than ever before, and there are no signs that indicate a possible reversal. Organizations can no longer exclusively rely on standard cybersecurity solutions like firewalls and antivirus software. Hackers are consistently improving their strategies and are now able to easily penetrate traditional…
13 Cybersecurity Standards You Must Know (Industry-Specific)
TL,DR: Cybersecurity standards provide structured guidance for protecting data, systems, and operations. Common standards support compliance, governance, risk management, and customer assurance. Selecting standards should depend on industry, business model, data sensitivity, and regulatory scope. USD 4.88M – That’s the average number of global data breaches in 2024. The exponential growth of cyber threats has…

Sprinto: Your growth superpower
Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.






