Authority Document added to the UCF
June 21, 2021
This UCF Authority Document concerns CobiT issued by ISACA
This UCF Authority Document concerns Georgia Code Title 46, Chapter 5, Article 6, Section 46-5-214, Action in event of telephone record security breach; notification to Georgia residents; law enforcement exception; violations shall be unfair or deceptive practice in consumer transactions issued by Georgia General Assembly
This UCF Authority Document concerns Georgia Code Title 46, Chapter 5, Article 6, Section 46-5-214, Action in event of telephone record security breach; notification to Georgia residents; law enforcement exception; violations shall be unfair or deceptive practice in consumer transactions issued by Georgia General Assembly
This UCF Authority Document concerns Mississippi Code Ann Title 75, Chapter 24, Section 75-24-29, Persons conducting business in Mississippi required to provide notice of a breach of security involving personal information to all affected individuals; enforcement issued by Mississippi State Legislature
This UCF Authority Document concerns Connecticut State Law, Section 36a-701b, Breach of security re computerized data containing personal information. Disclosure of breach. Delay for criminal investigation. Means of notice. Unfair trade practice issued by Connecticut General Assembly
This UCF Authority Document concerns 12 CFR Part 748, NCUA Guidelines for Safeguarding Member Information issued by US National Credit Union Administration
This UCF Authority Document concerns Appendix B of OCC 12 CFR Part 30, Safety and Soundness Standards issued by US Office of the Comptroller of the Currency (OCC)
This UCF Authority Document concerns ISO/IEC 27002:2013(E), Information technology — Security techniques — Code of practice for information security controls issued by International Organization for Standardization
This UCF Authority Document concerns ISO 27001:2013, Information Technology - Security Techniques - Information Security Management Systems - Requirements issued by International Organization for Standardization
This UCF Authority Document concerns ISO/IEC 27002:2013(E), Information technology — Security techniques — Code of practice for information security controls issued by International Organization for Standardization
This UCF Authority Document concerns ISO 27001:2013, Information Technology - Security Techniques - Information Security Management Systems - Requirements issued by International Organization for Standardization
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Requirements and Security Assessment Procedures issued by PCI Security Standards Council
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Self-Assessment Questionnaire B and Attestation of Compliance issued by PCI Security Standards Council
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance; Card-not-present Merchants, All Cardholder Data Functions Fully Outsourced issued by PCI Security Standards Council
This UCF Authority Document concerns EU-U.S. Privacy Shield Framework Principles issued by US Department of Commerce
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Requirements and Security Assessment Procedures issued by PCI Security Standards Council
This UCF Authority Document concerns Information Supplement: PCI DSS Wireless Guidelines issued by PCI Security Standards Council
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Self-Assessment Questionnaire P2PE and Attestation of Compliance issued by PCI Security Standards Council
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Self-Assessment Questionnaire C and Attestation of Compliance issued by PCI Security Standards Council
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Self-Assessment Questionnaire B-IP and Attestation of Compliance issued by PCI Security Standards Council
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Self-Assessment Questionnaire C-VT and Attestation of Compliance issued by PCI Security Standards Council
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Self-Assessment Questionnaire A-EP and Attestation of Compliance issued by PCI Security Standards Council
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Self-Assessment Questionnaire D and Attestation of Compliance for Service Providers issued by PCI Security Standards Council
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Self-Assessment Questionnaire D and Attestation of Compliance for Service Providers issued by PCI Security Standards Council
This UCF Authority Document concerns TSP 100 - Trust Services Principles and Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy issued by American Institute of Certified Public Accountants
This UCF Authority Document concerns New York Codes, Rules and Regulations, Title 23, Chapter 1, Part 500 Cybersecurity Requirements for Financial Services Companies issued by New York Department of Financial Services
This UCF Authority Document concerns Montana Code Annotated Title 33, Chapter 19, Part 3, Section 33-19-321 issued by Montana State Legislature
This UCF Authority Document concerns Connecticut General Statutes, Title 4e, Chapter 62a, Section 4e-70, Requirements for state contractors who receive confidential information issued by Connecticut General Assembly
This UCF Authority Document concerns Montana Code Annotated Title 2., Chapter 6., Part 15., Sections 2-6-1501 to 1503 issued by Montana State Legislature
This UCF Authority Document concerns Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations, NIST Special Publication 800-171 issued by US National Institute of Standards and Technology
This UCF Authority Document concerns How to Write an Extended Definition issued by Richard Corning
This UCF Authority Document concerns How to Write a Dictionary Definition issued by wikiHow
This UCF Authority Document concerns Insurance Data Security Model Law, NAIC MDL-668 issued by National Association of Insurance Commissioners
This UCF Authority Document concerns Standards for Safeguarding Customer Information Model Regulation, NAIC MDL-673 issued by National Association of Insurance Commissioners
This UCF Authority Document concerns AD Remapping Demo issued by Unified Compliance Framework
This UCF Authority Document concerns North American Electric Reliability Corporation Critical Infrastructure Protection Standards Cyber Security - BES Cyber System Categorization CIP-002-5.1a issued by North American Electric Reliability Corporation
This UCF Authority Document concerns North American Electric Reliability Corporation Critical Infrastructure Protection Standards Cyber Security - Electronic Security Perimeter(s) CIP-005-5 issued by North American Electric Reliability Corporation
This UCF Authority Document concerns North American Electric Reliability Corporation Critical Infrastructure Protection Standards Cyber Security - Physical Security of BES Cyber Systems CIP-006-6 issued by North American Electric Reliability Corporation
This UCF Authority Document concerns North American Electric Reliability Corporation Critical Infrastructure Protection Standards Cyber Security - Incident Reporting and Response Planning CIP-008-5 issued by North American Electric Reliability Corporation
This UCF Authority Document concerns North American Electric Reliability Corporation Critical Infrastructure Protection Standards Cyber Security - Recovery Plans for BES Cyber Systems CIP-009-6 issued by North American Electric Reliability Corporation
This UCF Authority Document concerns North American Electric Reliability Corporation Critical Infrastructure Protection Standards Cyber Security - Configuration Change Management and Vulnerability CIP-010-2 issued by North American Electric Reliability Corporation
This UCF Authority Document concerns North American Electric Reliability Corporation Critical Infrastructure Protection Standards Cyber Security - Information Protection CIP-011-2 issued by North American Electric Reliability Corporation
This UCF Authority Document concerns North American Electric Reliability Corporation Critical Infrastructure Protection Standards Physical Security CIP-014-2 issued by North American Electric Reliability Corporation
This UCF Authority Document concerns North American Electric Reliability Corporation Critical Infrastructure Protection Standards Cyber Security - Personnel & Training CIP-004-6 issued by North American Electric Reliability Corporation
This UCF Authority Document concerns North American Electric Reliability Corporation Critical Infrastructure Protection Standards Cyber Security - System Security Management CIP-007-6 issued by North American Electric Reliability Corporation
This UCF Authority Document concerns GDPR Information Assurance Audit Questions; A specialized audit of unique information governance controls found in GDPR issued by ARMA International
This UCF Authority Document concerns Framework for Improving Critical Infrastructure Cybersecurity issued by US National Institute of Standards and Technology
This UCF Authority Document concerns FFIEC Information Technology Examination Handbook - Management issued by US Federal Financial Institutions Examination Council (FFIEC)
This UCF Authority Document concerns FFIEC Cybersecurity Assessment Tool, Baseline issued by US Federal Financial Institutions Examination Council (FFIEC)
This UCF Authority Document concerns New York Codes, Rules and Regulations, Title 23, Chapter 1, Part 500 Cybersecurity Requirements for Financial Services Companies issued by New York Department of Financial Services
This UCF Authority Document concerns Montana Code Annotated Title 33, Chapter 19, Part 3, Section 33-19-321 issued by Montana State Legislature
This UCF Authority Document concerns New York State Technology Law, Article 2 Internet Security and Privacy Act issued by New York State Legislature
This UCF Authority Document concerns Ohio Revised Code, Title 13, Chapter 1349, Section 1349.191 Investigation of noncompliance with disclosure laws.. issued by Ohio State General Assembly
This UCF Authority Document concerns Ohio Revised Code, Title 13, Chapter 1349, Section 1349.192 Civil action by attorney general for violation of disclosure laws. issued by Ohio State General Assembly
This UCF Authority Document concerns Tennessee Code Annotated Title 8, Chapter 4, Part 1, Section 8-4-119 Report to comptroller of treasury of government fraud. issued by Tennessee General Assembly
This UCF Authority Document concerns Revised Code of Washington Title 42, Chapter 42.56, Section 42.56.590 Personal information--Notice of security breaches. issued by Washington State Legislature
This UCF Authority Document concerns Code of Virginia Title 32.1, Chapter 5., Section 32.1-127.1:05 Breach of medical information notification. issued by Virginia General Assembly
This UCF Authority Document concerns Code of Maryland State Government, Title 10, Subtitle 13, Sections 10-1301 to 10-1308 issued by Maryland General Assembly
This UCF Authority Document concerns New Mexico House Bill 15, Data Breach Notification Act issued by New Mexico State Legislature
This UCF Authority Document concerns Connecticut General Statutes, Title 4e, Chapter 62a, Section 4e-70, Requirements for state contractors who receive confidential information issued by Connecticut General Assembly
This UCF Authority Document concerns Montana Code Annotated Title 2., Chapter 6., Part 15., Sections 2-6-1501 to 1503 issued by Montana State Legislature
This UCF Authority Document concerns Florida Statutes, Title XXXII, Chapter 501, Section 501.171, Security of confidential personal information issued by Florida State Legislature
This UCF Authority Document concerns Arizona Revised Statutes Title 18, Chapter 5, Article 3, Section 18-545, Notification of breach of security system; enforcement; civil penalty; preemption; exceptions; definitions issued by Arizona State Legislature
This UCF Authority Document concerns FFIEC IT Examination Handbook - Audit issued by US Federal Financial Institutions Examination Council (FFIEC)
This UCF Authority Document concerns FFIEC Information Technology Examination Handbook - Information Security issued by US Federal Financial Institutions Examination Council (FFIEC)
This UCF Authority Document concerns FFIEC Business Continuity Planning (BCP) IT Examination Handbook issued by US Federal Financial Institutions Examination Council (FFIEC)
This UCF Authority Document concerns ISO/IEC 27017:2015, Information technology -- Security techniques -- Code of practice for information security controls based on ISO/IEC 27002 for cloud services issued by International Organization for Standardization
This UCF Authority Document concerns ISO 704:2009 Terminology work -- Principles and methods issued by International Organization for Standardization
This UCF Authority Document concerns Hong Kong Monetary Authority: TM-G-1: General Principles for Technology Risk Management issued by Hong Kong Monetary Authority
This UCF Authority Document concerns Monetary Authority of Singapore: Technology Risk Management Guidelines issued by Monetary Authority of Singapore
This UCF Authority Document concerns Guam 9 GCA, Chapter 48, Notification of Breaches of Personal Information issued by Guam Legislature
This UCF Authority Document concerns Security and Privacy Controls for Federal Information Systems and Organizations, NIST SP 800-53, High Impact Baseline issued by US National Institute of Standards and Technology
This UCF Authority Document concerns Security and Privacy Controls for Federal Information Systems and Organizations, NIST SP 800-53, Moderate Impact Baseline issued by US National Institute of Standards and Technology
This UCF Authority Document concerns Security and Privacy Controls for Federal Information Systems and Organizations, NIST SP 800-53, Low Impact Baseline issued by US National Institute of Standards and Technology
This UCF Authority Document concerns Security and Privacy Controls for Federal Information Systems and Organizations, NIST SP 800-53 issued by US National Institute of Standards and Technology
This UCF Authority Document concerns Insurance Data Security Model Law, NAIC MDL-668 issued by National Association of Insurance Commissioners
This UCF Authority Document concerns Privacy of Consumer Financial and Health Information Regulation, NAIC MDL-672 issued by National Association of Insurance Commissioners
This UCF Authority Document concerns Insurance Data Security Model Law, NAIC MDL-668 issued by National Association of Insurance Commissioners
This UCF Authority Document concerns Privacy of Consumer Financial and Health Information Regulation, NAIC MDL-672 issued by National Association of Insurance Commissioners
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Requirements and Security Assessment Procedures issued by PCI Security Standards Council
This UCF Authority Document concerns ISO 27001:2013, Information Technology - Security Techniques - Information Security Management Systems - Requirements issued by International Organization for Standardization
This UCF Authority Document concerns Payment Card Industry (PCI) Data Security Standard, Testing Procedures issued by PCI Security Standards Council
This UCF Authority Document concerns Trust Services Criteria issued by American Institute of Certified Public Accountants
This UCF Authority Document concerns Principles for Businesses issued by The Financial Conduct Authority
This UCF Authority Document concerns Canada Personal Information Protection and Electronic Documents Act issued by Parliament of Canada
This UCF Authority Document concerns FFIEC IT Examination Handbook - Retail Payment Systems issued by US Federal Financial Institutions Examination Council (FFIEC)
This UCF Authority Document concerns Directive (EU) 2016/1148 OF The European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union issued by European Parliament
This UCF Authority Document concerns Framework for Improving Critical Infrastructure Cybersecurity issued by US National Institute of Standards and Technology
This UCF Authority Document concerns ISO 31000 Risk management - Guidelines issued by International Organization for Standardization
This UCF Authority Document concerns Hong Kong Monetary Authority Supervisory Policy Manual TM-E-1 Risk Management of E-Banking issued by Hong Kong Monetary Authority
This UCF Authority Document concerns Enterprise Risk Management - Integrating with Strategy and Performance issued by Committee of Sponsoring Organizations of the Treadway Commission
This UCF Authority Document concerns ISO 9001 Quality Management systems - Requirements issued by International Organization for Standardization
This UCF Authority Document concerns Australian Privacy Act 1988 issued by Parliament of Australia
This UCF Authority Document concerns CIS Controls issued by The Center for Internet Security
This UCF Authority Document concerns Colorado Revised Statutes, Section 6-1-716, Notice of Security Breach issued by Colorado State Legislature
This UCF Authority Document concerns California Civil Code Division 3 Part 4 Title 1.81.5 California Consumer Privacy Act of 2018 issued by California Legislature
This UCF Authority Document concerns Digital Identity Guidelines: Enrollment and Identity Proofing issued by US National Institute of Standards and Technology
This UCF Authority Document concerns 2017 New Mexico Statutes Chapter 57 - Trade Practices and Regulations Article 12C - Data Breach Notification Section 57-12C-1 issued by New Mexico State Legislature
This UCF Authority Document concerns California Civil Code Title 1.81 Customer Records § 1798.80-1798.84 issued by California Legislature
This UCF Authority Document concerns Tennessee Code, Title 47, Chapter 1,8 Part 21, Identity Theft Deterrence, Sections 47-18-2101 thru 47-18-2110 issued by Tennessee General Assembly