Skip to content

Monthly Selected Authority Documents - February, 2017

Here is a list of the 50 most selected Authority Documents in the Common Controls Hub this past...

Here is a list of the 50 most selected Authority Documents in the Common Controls Hub this past month. We also list how many groups each Authority Document has been assigned to and how many initiatives it has been assigned to.

AD Common Name AD Type Selected Groups Initiatives
ISO 27001-2013 International or National Standard 46 23 13
PCI DSS Requirements and Security Assessment Procedures Contractual Obligation 43 5 0
CobiT Safe Harbor 28 18 6
NIST SP 800-53 R4 International or National Standard 28 7 5
ISO 27002 International or National Standard 27 9 6
ISO/IEC 27002:2013(E) International or National Standard 26 8 6
FFIEC Information Security Best Practice Guideline 23 5 3
PCI DSS 3.1 Contractual Obligation 23 3 2
NIST SP 800-53 R4 High Impact International or National Standard 22 11 3
CSIS 20 Critical Security Controls Best Practice Guideline 21 10 4
NIST Framework for Improving Critical Infrastructure Cybersecurity International or National Standard 21 10 8
Sarbanes Oxley SOX Regulation or Statute 21 17 12
NIST SP 800-171 International or National Standard 20 3 1
NIST SP 800-53 R4 Moderate Impact International or National Standard 18 7 5
Gramm Leach Bliley Bill or Act 17 8 5
NIST SP 800-53 International or National Standard 17 5 3
PCI SAQ A v3.1 Contractual Obligation 16 2 1
AICPA Reporting on Controls at a Service Organization SOC-2 Safe Harbor 15 9 3
HIPAA Bill or Act 14 13 8
FedRAMP Baseline Security Controls Audit Guideline 13 8 3
FFIEC Management Best Practice Guideline 13 3 0
FFIEC Retail Payment Systems Best Practice Guideline 13 3 0
FFIEC Audit Best Practice Guideline 12 3 0
FFIEC Business Continuity Planning Best Practice Guideline 12 3 0
FFIEC Development Acquisition Best Practice Guideline 12 3 0
FFIEC E Banking Best Practice Guideline 12 3 0
FFIEC Operations Best Practice Guideline 12 3 0
FFIEC Outsourcing Technology Services Best Practice Guideline 12 4 1
FFIEC Supervision of Technology Service Providers Best Practice Guideline 12 4 1
FFIEC Wholesale Payment Systems Best Practice Guideline 12 3 0
SSAE No. 16 Reporting on Controls at a Service Organization SOC-1 Safe Harbor 12 5 3
UK Data Protection Act of 1998 Regulation or Statute 12 11 6
Authentication in an Internet Banking Environment Best Practice Guideline 11 3 0
ISO 20000-1 2nd Ed International or National Standard 11 6 3
ISO 27005 R 2011 International or National Standard 11 7 5
ISO 31000 R 2009 International or National Standard 11 12 3
France Data Protection Act Regulation or Statute 10 6 4
Germany Data Protection Act Regulation or Statute 10 4 2
NIST SP 800 66 Safe Harbor 10 9 6
16 CFR Part 313 Regulation or Statute 9 7 5
BSI-Standard 100-2 International or National Standard 9 3 0
Cloud Controls Matrix, Version 3.0 Self-Regulatory Body Requirement 9 1 1
EU Data Protection Directive 95 46 EC International or National Standard 9 9 7
EU Directive on privacy and electronic communications International or National Standard 9 10 6
ISO 20000-2 R 2005 International or National Standard 9 6 3
ITIL Security Management Best Practice Guideline 9 5 3
NIST 800-53A International or National Standard 9 5 3
South African King Report 2002 Regulation or Statute 9 8 5
Sweden Personal Data Act Regulation or Statute 9 4 2
45 CFR Part 164 Regulation or Statute 8 8 4