Compliance is the discipline of meeting the external and internal obligations that apply to an organization's handling of information and systems. These obligations come from laws and regulations, contractual commitments, industry standards, and the organization's own policies. Examples include data protection law, sector rules for finance or healthcare, and certification requirements that customers expect suppliers to hold.
Compliance occupies a central place in governance because it translates abstract legal and regulatory language into concrete, testable control requirements. It connects the organization's obligations to the policies, procedures, and technical measures that satisfy them, and it provides evidence that those obligations are being met.
Why it matters is straightforward: non-compliance can bring fines, loss of certification, contract termination, and reputational harm. Beyond avoiding penalties, a mature compliance posture builds trust with customers, regulators, and partners, and often raises the overall quality of the security program.
Compliance work involves identifying applicable requirements, mapping them to a control framework, assigning ownership, collecting evidence, and monitoring continuously. Mapping requirements to a common framework avoids duplicated effort when several obligations overlap, letting one well-implemented control satisfy many demands at once.
References#
- ISO/IEC 27001 and ISO/IEC 27002, which provide a management system and a catalog of information security controls.
- NIST Cybersecurity Framework (CSF), which helps map obligations to control outcomes.