Compliance & Frameworks
Compliance
Also known as: Regulatory compliance, Security compliance
Definition
The discipline of meeting legal, regulatory, contractual, and internal security requirements through documented controls, evidence collection, and ongoing assessment.
Examples
- A SaaS provider undergoing a SOC 2 Type II audit to satisfy enterprise customers.
- A retailer maintaining PCI DSS controls to process payment card data.
Related terms
ISO/IEC 27001
The international standard specifying requirements for an Information Security Management System (ISMS), against which organizations can be formally certified.
SOC 2
SOC 2 — definition coming soon.
PCI DSS
A global information-security standard for organizations that store, process, or transmit payment card data, maintained by the PCI Security Standards Council.
GDPR
The European Union's General Data Protection Regulation governing the processing of personal data of individuals in the EU and EEA.
NIST Cybersecurity Framework
A voluntary risk-based framework published by the U.S. National Institute of Standards and Technology that organizes cybersecurity outcomes into six core functions.
Security Controls
Safeguards or countermeasures — technical, administrative, or physical — used to prevent, detect, or respond to threats against information assets.