Learn
Compliance & Security,
Explained
Plain-English guides to the concepts behind ISO 27001, SOC 2, and the DPDP Act — written by certified auditors, not marketers. Start with the fundamentals below, or browse the full glossary.
A growing knowledge base · Last reviewed June 2026
Start with the fundamentals
What Is an ISMS?
Information Security Management System explained — the framework of policies, processes, and controls at the heart of ISO 27001.
Read the guideWhat Is GRC?
Governance, Risk & Compliance — the three pillars, why they belong together, and how they map to ISO 27001, SOC 2, and DPDP.
Read the guideRisk Management Frameworks
NIST RMF, ISO 31000, ISO 27005, COSO ERM, and FAIR — what each is for, and how to choose the right one.
Read the guideData Governance Frameworks
Managing data as an asset — DAMA-DMBOK, DCAM, and how data governance maps to the DPDP Act and GDPR.
Read the guideData Privacy Laws in India
The full landscape — the DPDP Act 2023, the DPDP Rules 2025, the legacy IT Act framework, and the RBI/SEBI/IRDAI overlays that sit on top.
Read the guideWhat Is a Data Fiduciary?
The DPDP Act’s equivalent of a data controller — how it differs from a data processor and a data principal, and what obligations it carries.
Read the guideDPDP Full Form & Meaning
DPDP = Digital Personal Data Protection. What the DPDP Act, 2023 is, who it applies to, and the key terms in plain English.
Read the guideWhat Is Access Control?
Who can access what — the models (DAC, MAC, RBAC, ABAC), least privilege, and its role in ISO 27001 & SOC 2.
Read the guideNIST Cybersecurity Framework
CSF 2.0 explained — the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Tiers, Profiles, and how it maps to ISO 27001.
Read the guideInformation Security Policy
The top-level security document — what it must cover, the policy hierarchy, and why ISO 27001 Clause 5.2 requires one.
Read the guideCUECs & CSOCs Explained
The controls a SOC report assumes of you and of carved-out vendors — plus the carve-out vs inclusive method, in plain English.
Read the guideWhat Is AT-C Section 320?
The AICPA attestation section behind SOC 1 — the AT-C 105/205/320 architecture, the system-description elements, and management-defined control objectives.
Read the guideSSAE 18 vs SSAE 21
Which standard is current in 2026 — the SSAE 18→23 lineage with effective dates, and why SOC 1 still runs on AT-C 320.
Read the guideSOC 1 Description Criteria
Why SOC 1 has no DC 200 — the AICPA description criteria apply to SOC 2 only; SOC 1’s requirements live inside AT-C 320.
Read the guideSOC 1 Bridge Letters
Gap letters between report periods — who signs them, what they must contain, and what they can never replace.
Read the guideWhat Is SOC 2?
The AICPA attestation for service organizations — the five Trust Services Categories, Type 1 vs Type 2, and what "SOC 2 compliant" really means.
Read the guideHow to Read a SOC 2 Report
The five sections explained — auditor’s opinion, management’s assertion, system description, test results — plus the red flags reviewers check first.
Read the guideSOC 2 Opinions & Exceptions
Unmodified, qualified, adverse, disclaimer — what each auditor opinion means, how test exceptions differ, and how to respond to both.
Read the guideWho Can Perform a SOC 2 Audit?
Only a licensed CPA firm can issue a SOC 2 report — what that means, how independence works, and where consultants and platforms fit.
Read the guideSubservice Organizations
Carve-out vs inclusive method — how your vendors’ vendors appear in a SOC report, and the monitoring you inherit.
Read the guideSOC 2 Controls List
There is no official list — illustrative controls by criteria series (CC1–CC9 and beyond), and how to design your own set.
Read the guideSOC 2 Compliance Checklist
Six phases from first scoping call to annual maintenance — with the concrete checkpoints auditors expect at each.
Read the guideTypes of SOC Reports
SOC 1 vs SOC 2 vs SOC 3 — audiences, criteria, restricted vs general use, and which report your customers are actually asking for.
Read the guideYour SOC 2 Is In Progress — What to Tell Customers
What you can honestly claim mid-journey — readiness letters, timeline language, and questionnaire answers that hold up.
Read the guideSOC 2 for Enterprise Sales
How a report actually moves security reviews and procurement — and the deals it won’t close on its own.
Read the guideAnatomy of a SOC 2 Report (Interactive)
A SOC 2 Type II report you can dissect — 18 clickable markers explain the opinion, assertion, description, and test matrix.
Read the guideSOC 2 Common Pitfalls
The ten predictable mistakes that stall first examinations — scoping, operating-period, and fieldwork — and what to do instead.
Read the guideAI Risk vs AI Impact Assessment
The most-confused distinction in ISO 42001 — clause 6.1.2 risk (inward) vs 6.1.4 impact (outward, per ISO/IEC 42005), and how both feed the SoA.
Read the guideWhich AI Role Are You?
Provider, deployer, producer, user — and the four scenarios: API wrappers, fine-tuners, self-hosters, and internal-only AI use.
Read the guideISO 42001 + ISO 27001 Integration
One integrated system, two certificates — what your ISMS already gives you, the genuinely new AIMS artifacts, and combined audits.
Read the guideISO 42001 Accreditation & ISO 42006
Not all certificates are equal — accredited vs unaccredited, ISO/IEC 42006:2025, and the 30-minute IAF CertSearch verification.
Read the guideISO 42001 vs the EU AI Act
Voluntary standard vs binding law — the post-omnibus timeline (Annex III from Dec 2027), what an AIMS evidences, and what it can’t.
Read the guideISO 42001 vs NIST AI RMF
GOVERN, MAP, MEASURE, MANAGE crosswalked to clauses and controls — and the certifiability difference that decides adoption.
Read the guideLooking for a specific term? The compliance glossary defines the acronyms and concepts across ISO 27001, SOC 2, DPDP, HIPAA, and more — and more in-depth guides are on the way.
Get in touch
Book a free consultation or send us your requirements. We respond within 24 hours.
Quick Call
Pick a time slot
Send Requirements
Get a custom quote in 24 hours