166 terms · 75/46/45
Defense № 043 · class: governance

Regulatory Compliance

Meeting requirements of regulatory frameworks and standards for cybersecurity.

Term

description · examples · notes

Meeting requirements of regulatory frameworks and standards for cybersecurity.

Description

Includes GDPR, NIS2, ISO 27001, SOC 2, PCI DSS, and local regulations.

Requires documenting controls, regular audits, and reporting.

Non-compliance can result in fines, loss of licenses, or reputation.

Compliance is not the same as security — it is possible to be compliant but insecure.

What people often say

  • Compliance does not mean security — many breaches happen to compliant organizations.
  • ISO 27001 certification does not guarantee that an incident will not occur.

Covers / does not cover

Covers

  • Audit and certification (ISO 27001)
  • Personal data protection (GDPR)
  • Sector requirements (PCI DSS for payments)

Does not cover

  • Operational security beyond regulatory requirements
  • Technical implementation (the security team does that)
  • Protection from advanced threats not covered by regulation

Mentioned in the news

Composite

Threats

reduces 3

Threats it reduces. Select one to open its page.

Techniques

neutralizes 3

Techniques it neutralizes. Select one to open its page.