Compliance

Compliance means satisfying the obligations placed on an organization by laws, regulations, industry standards, and contracts. Healthcare answers to HIPAA, card processors to PCI DSS, public companies to SOX. Fall short and the consequences stack up: fines, legal liability, lost business, and reputational harm that outlasts the penalty itself.

A compliance program maps applicable requirements to specific controls, implements them, monitors whether they hold, and keeps evidence ready for auditors and regulators. The judgment worth remembering is that compliance is a floor, not a ceiling. Meeting a standard proves you cleared its minimum bar on the day you were measured; it does not prove you are secure against a determined attacker. Teams that chase the checklist and stop there tend to pass audits and still get breached. Mapping one control to several requirements at once keeps the program efficient instead of duplicating effort across overlapping regimes.

Why does compliance matter for the CISSP exam?

Legal and regulatory requirements fall under Domain 1: Security and Risk Management. Know the major regimes such as HIPAA, GDPR, SOX, GLBA, and PCI DSS, how they apply by industry, and why security professionals coordinate closely with legal counsel on these matters.