Regulatory Compliance
Meeting requirements of regulatory frameworks and standards for cybersecurity.
Term
description · examples · notesMeeting requirements of regulatory frameworks and standards for cybersecurity.
Description
Includes GDPR, NIS2, ISO 27001, SOC 2, PCI DSS, and local regulations.
Requires documenting controls, regular audits, and reporting.
Non-compliance can result in fines, loss of licenses, or reputation.
Compliance is not the same as security — it is possible to be compliant but insecure.
What people often say
- Compliance does not mean security — many breaches happen to compliant organizations.
- ISO 27001 certification does not guarantee that an incident will not occur.
Covers / does not cover
Covers
- Audit and certification (ISO 27001)
- Personal data protection (GDPR)
- Sector requirements (PCI DSS for payments)
Does not cover
- Operational security beyond regulatory requirements
- Technical implementation (the security team does that)
- Protection from advanced threats not covered by regulation
Mentioned in the news
Threats
reduces 3Threats it reduces. Select one to open its page.
Techniques
neutralizes 3Techniques it neutralizes. Select one to open its page.