Compliance
What is Compliance?
The state of conforming to laws, regulations, standards, or internal policies. In information security, compliance is typically demonstrated through audits, certifications, and continuous monitoring.
Related terms
Frameworks that govern compliance
What the standards actually require on compliance
Requirements naming compliance across 6 standards, quoted from the control text.
Per PSTI: Defined Support Period (Minimum Security Update Period Declaration) + Statement of Compliance + Manufacturer Identification.
UKPSTIACT-3 · Defined Support Period and Statement of Compliance →FLA Accreditation is the multi-year assurance mechanism by which FLA Member Companies + Supplier Companies + Universities + Civil Society Organisations demonstrate sustained implementation of the Workplace Code of Conduct.
FLA-Accreditation · FLA Accreditation, Independent External Monitoring and Sustainable Compliance Initiative →Requirement defined in ISO 37301:2021, clause 5.2 (Compliance policy). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.
iso-37301-2021::5.2 · Compliance policy →Applicable legislation and contractual requirements must be identified, and the organization should identify the potential legal sanctions arising from missed obligations for the processing of personal data, including substantial fines from a supervisory autho...
iso-27701-2019::6.15.1 · Compliance with legal and contractual requirements →Sections 45-50 of the Jamaica Data Protection Act 2020 establish the complaints and enforcement framework. (1) Section 45 Right to Complain: (a) data subject may complain to OIC against controller or processor;
JM-DPA2020-Complaints-Enforcement-Sec45-50-Investigation-Hearing-Determination-Appeal-Tribunal · Jamaica DPA 2020 Complaints + Enforcement + Sections 45-50 + Complaint Procedure + Investigation + Hearing + Determination + Compliance Orders + Administrative Penalties + Data Protection Tribunal + High Court Appeals →Providers of high-risk AI systems shall ensure compliance with the Section 2 requirements (Arts 9-15), taking into account the intended purpose, the generally acknowledged state of the art and the integration of the AI system into other systems.
EUAI-Art.8 · Compliance with the requirements →Questions people ask about compliance
What is Compliance?
Why is Compliance important for compliance?
What concepts are related to Compliance?
Which compliance frameworks address Compliance?
Where can I learn more about Compliance?
See how Compliance applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.