D1 · General

What is regulatory compliance in security?

Regulatory compliance meets legal and industry security requirements — GDPR (EU data privacy), HIPAA (healthcare), PCI DSS (payment cards), SOX (financial), FISMA (US federal).
Compliance ≠ security. You can be compliant but insecure, or secure but non-compliant. Compliance sets a floor, not a ceiling. Most frameworks drive meaningful security improvements, but shouldn't replace risk-based thinking.
← Back to Glossary Practice Questions →