Compliance

Conforming to laws, regulations, contractual terms, and internal policy.

Compliance means conforming to external mandates (laws, regulations, contracts like PCI DSS) and internal policy. The critical exam point: compliance is the floor, not the ceiling — an organization can pass every audit and still be insecure, because frameworks lag real threats. Continuous control monitoring lowers the cost and pain of point-in-time audits and keeps the gap between “compliant” and “secure” small.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Security Program Management and Oversight