tags

Monthly Selected Authority Documents  December, 2023

Monthly Selected Authority Documents  December, 2023

By Matt Hill · January 4, 2024

 

Here is a list of the 50 most selected Authority Documents in the Common Controls Hub this past month. We also list how many groups each Authority Document has been assigned to and how many initiatives it has been assigned to.

AD Common NameAD TypeSelectedGroupsInitiativesNIST CSF 1.1International or National Standard386123ISO/IEC 27001:2022International or National Standard30104CIS Controls, V8Best Practice Guideline28139EU General Data Protection Regulation (GDPR)Regulation or Statute2518519ISO 27001-2013International or National Standard2221622PCI DSS v3.2.1Contractual Obligation2084PCI DSS Defined Approach Requirements, Version 4.0International or National Standard1884ISO/IEC 27002:2022International or National Standard171010Sarbanes-Oxley Act of 2002Bill or Act1656ISO/IEC 27017:2015(E)Self-Regulatory Body Requirement152311TSP Section 100: 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and PrivacySelf-Regulatory Body Requirement146223 NYCRR 500Regulations1311AICPA Trust ServicesAudit Guideline1361CIS Controls, V7.1Best Practice Guideline1384ISO/IEC 27018:2019International or National Standard1332NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsInternational or National Standard13158NIST SP 800-53 R5International or National Standard132717ISO/IEC 27701:2019International or National Standard12189AICPA Reporting on Controls at a Service Organization SOC-2Safe Harbor111447FFIEC Information Technology Examination Handbook - Business Continuity ManagementAudit Guideline11205FFIEC IT Examination Handbook Architecture, Infrastructure, and Operations 2021Audit Guideline1150Gramm Leach BlileyBill or Act1130BSI Cloud Computing Compliance Controls Catalogue (C5)Best Practice Guideline10184FedRAMP Security Controls Baseline, 2018Audit Guideline1014FFIEC CATBest Practice Guideline10231FFIEC IT Examination HandbookAudit Guideline10222FFIEC Outsourcing Technology ServicesBest Practice Guideline10130FINRA Report on Cybersecurity PracticesSelf-Regulatory Body Requirement1091Hong Kong Monetary Authority: The Cyber Resilience Assessment Framework, 18 May 2016Best Practice Guideline1030MAS-TRMG-2021Contractual Obligation1070NFA Information Systems Security ProgramsSelf-Regulatory Body Requirement10151NIST CSF 1.0International or National Standard10122Notice on Cyber HygieneBill or Act10110UK Data Protection Act 2018Bill or Act10200Australia Privacy Amendment ActRegulation or Statute9200Cloud Controls Matrix, v4.0Self-Regulatory Body Requirement950Control Baselines for Information Systems and Organizations, NIST Special Publication 800-53B, High Impact Baseline, October 2020International or National Standard9108Control Baselines for Information Systems and Organizations, NIST Special Publication 800-53B, Moderate Impact Baseline, October 2020International or National Standard9115COSO Enterprise Risk Management (2017)Best Practice Guideline9259COSO ERMSafe Harbor9118FFIEC Development AcquisitionBest Practice Guideline9140HKMA General Principles for Technology Risk ManagementRegulation or Statute9280Hong Kong Personal Data (Privacy) Ordinance 2013Bill or Act980ISO 27002International or National Standard984MAS Guidelines on OutsourcingBill or Act910MAS TRMContractual Obligation9480NIST SP 800-122International or National Standard9229NIST SP 800-39International or National Standard9196NIST SP 800-53 R4International or National Standard953NIST SP 800-53 Revision 5.1.1International or National Standard900{{ include_custom_fonts({"Aeonik":["Regular","Bold"]}) }}

Ready to see your fabric?

Request a demo of ControlSight and see how Unified Compliance connects mandates, policies, and controls into one living fabric.