Skip to content

Monthly Selected Authority Documents October 2024

Here is a list of the 50 most selected Authority Documents in the Common Controls Hub this past month. We also list how many groups each Authority Document has been assigned to and how many initiatives it has been assigned to.

AD_Name AD_id AD_type selected groups initiatives
ISO/IEC 27001:2022 3567 International or National Standard 53 10 4
NIST CSF 2.0 3789 International or National Standard 47 4 1
ISO/IEC 27002:2022 3430 International or National Standard 35 12 10
NIST SP 800-53 R5 3241 International or National Standard 25 31 18
EU General Data Protection Regulation (GDPR) 2802 Regulation or Statute 24 190 21
SOC 2®, 2022 3647 Audit Guideline 22 3 0
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, 14 December, 2022 3714 Regulatory Directive or Guidance 20 7 4
Sarbanes-Oxley Act of 2002 3296 Bill or Act 20 7 6
CIS Controls, V8 3323 Best Practice Guideline 19 13 9
hipaa security rule 3204 Regulation or Statute 19 7 2
NIST CSF 1.1 2934 International or National Standard 17 65 23
NIST SP 800-53 Revision 5.1.1 3687 International or National Standard 17 1 1
HIPAA 3201 Bill or Act 16 10 4
Digital Operational Resilience Act 3668 Regulations 15 5 2
ISO 27001-2013 1367 International or National Standard 14 221 23
CobiT 102 Safe Harbor 13 168 2
PCI DSS Defined Approach Requirements, Version 4.0 3444 International or National Standard 13 17 6
Cloud Controls Matrix, v4.0 3303 Self-Regulatory Body Requirement 12 6 1
ISO/IEC 27017:2015(E) 2838 Self-Regulatory Body Requirement 12 23 11
NIST AI 100-1 3591 Best Practice Guideline 12 1 0
23 NYCRR 500 3686 Regulations 11 8 6
23 NYCRR 500 2895 Regulation or Statute 11 36 11
California Privacy Rights Act (CPRA) 3290 Bill or Act 11 5 3
CSF V1.1 3709 International or National Standard 11 0 0
ISO/IEC 27701:2019 3020 International or National Standard 11 20 10
NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations 3134 International or National Standard 11 17 10
ISO 9001:2015 2942 International or National Standard 10 23 6
45 CFR Part 164 Subpart D 3729 Regulations 9 0 0
California Consumer Privacy Act of 2018 2957 Bill or Act 9 45 2
CIS Controls Version 8.1 3955 Best Practice Guideline 8 0 0
COBIT 2019 3009 Safe Harbor 8 9 2
COBIT 5 Enabling Processes: Basics 2935 Safe Harbor 8 55 3
COSO Enterprise Risk Management (2017) 2947 Best Practice Guideline 8 26 9
NIST SP 800-37r2 3013 International or National Standard 8 14 5
PCI DSS Defined Approach Testing Procedures, Version 4.0 3445 International or National Standard 8 10 6
PCI DSS Requirements and Security Assessment Procedures 2794 Contractual Obligation 8 159 8
Red Book (Condensed) 2840 International or National Standard 8 21 7
SWIFT Customer Security Controls Framework 3006 Best Practice Guideline 8 1 0
AICPA Reporting on Controls at a Service Organization SOC-2 1132 Safe Harbor 7 144 8
AICPA Trust Services 1176 Audit Guideline 7 8 2
Artificial Intelligence Act 3972 Regulations 7 0 0
CMMC Level 1, v2.0 3426 Best Practice Guideline 7 9 5
CMMC Level 2, v2.0 3427 Best Practice Guideline 7 11 6
Cyber Assessment Framework 3612 Best Practice Guideline 7 1 1
Gramm Leach Bliley 3302 Bill or Act 7 11 0
HIPAA HCFA 3200 Best Practice Guideline 7 4 4
ISO 22301:2019(E) 3454 International or National Standard 7 1 2
ISO 27002 482 International or National Standard 7 8 5
NIST 800-171 Rev 3 3946 International or National Standard 7 0 0
NIST CSF 1.0 1365 International or National Standard 7 13 2