Compliance
Noun · Security & Infosec
Definitions
Adherence to laws, regulations, standards, and internal policies governing data handling, security, and operations. Common frameworks include SOC 2, GDPR, HIPAA, PCI-DSS, and ISO 27001. Compliance is necessary but not sufficient for actual security.
In plain English: Following the official rules and regulations about how a company should handle data, security, and privacy.
Example: "We're SOC 2 compliant. That means we documented all the ways we could get hacked and promised to feel bad about it."