Skip to content

Monthly Selected Authority Documents - June, 2018

Here is a list of the 50 most selected Authority Documents in the Common Controls Hub this past...

Here is a list of the 50 most selected Authority Documents in the Common Controls Hub this past month. We also list how many groups each Authority Document has been assigned to and how many initiatives it has been assigned to.



AD Common Name AD Type Selected Groups Initiatives
ISO 27001-2013 International or National Standard 71 99 20
PCI DSS Requirements and Security Assessment Procedures Contractual Obligation 44 68 8
EU General Data Protection Regulation (GDPR) Regulation or Statute 37 62 3
Sarbanes Oxley SOX Regulation or Statute 31 71 16
AICPA Reporting on Controls at a Service Organization SOC-2 Safe Harbor 27 39 4
NIST Cybersecurity Framework International or National Standard 27 4 2
NIST SP 800-53 R4 International or National Standard 25 46 8
Red Book (Condensed) International or National Standard 24 1 1
NIST SP 800-53 R4 High Impact International or National Standard 22 77 4
NIST SP 800-53 R4 Moderate Impact International or National Standard 21 22 6
HIPAA Bill or Act 16 41 8
NIST SP 800-53 R4 Low Impact International or National Standard 16 18 4
HIPAA Electronic Health Record Technology Regulation or Statute 15 7 3
Gramm Leach Bliley Bill or Act 14 12 10
ISO 27002 International or National Standard 13 10 7
NIST SP 800 66 Safe Harbor 13 8 5
SSAE No. 16 Reporting on Controls at a Service Organization SOC-1 Safe Harbor 13 11 3
CobiT Safe Harbor 12 84 6
23 NYCRR 500 Regulation or Statute 11 0 6
CISWIG 1 Best Practice Guideline 11 4 1
India Indian Info Privacy Act Regulation or Statute 11 6 0
NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations International or National Standard 11 0 2
FFIEC Audit April 2012 Best Practice Guideline 10 0 0
FFIEC Business Continuity Planning Handbook 2015 Audit Guideline 10 0 0
PCI SAQ A v3.1 Contractual Obligation 10 5 1
AICPA Trust Services Audit Guideline 9 5 1
FFIEC CAT Best Practice Guideline 9 0 0
HIPAA HCFA Best Practice Guideline 9 16 2
ISO/IEC 27017:2015(E) Self-Regulatory Body Requirement 9 0 0
45 CFR Part 164 Regulation or Statute 8 13 6
CISWIG 2 Safe Harbor 8 5 2
CSIS 20 Critical Security Controls Best Practice Guideline 8 77 4
FFIEC IT Examination Handbook Audit Guideline 8 0 0
FFIEC Management 2015 Best Practice Guideline 8 0 0
FFIEC Supervision of Technology Service Providers Best Practice Guideline 8 6 1
ISO 31000 R 2009 International or National Standard 8 77 4
ISO/IEC 27002:2013(E) International or National Standard 8 78 16
PCI SAQ A v3.2 Contractual Obligation 8 0 0
PCI SAQ D Contractual Obligation 8 6 3
AICPA Trust Services Principles and Criteria Self-Regulatory Body Requirement 7 2 1
CIS 20 Critical Security Controls Best Practice Guideline 7 5 2
Cloud Security Alliance CCM V1.3 Best Practice Guideline 7 12 6
FFIEC Operations Best Practice Guideline 7 5 0
FFIEC Retail Payment Systems Best Practice Guideline 7 5 0
HKMA Supervisory Policy Manual TM-G-2 Business Continuity Planning Contractual Obligation 7 6 0
India Clause 49 Regulation or Statute 7 7 0
ISO/IEC 27018:2014 International or National Standard 7 4 3
Notice on Technology Risk Management, Notice No. CMG-N02 Self-Regulatory Body Requirement 7 6 0
Australian Government Information Security Manual Controls International or National Standard 6 6 3
Bank Secrecy Act Regulation or Statute 6 3 0