Skip to content

Monthly Selected Authority Documents - October, 2018

Here is a list of the 50 most selected Authority Documents in the Common Controls Hub this past...

Here is a list of the 50 most selected Authority Documents in the Common Controls Hub this past month. We also list how many groups each Authority Document has been assigned to and how many initiatives it has been assigned to.



AD Common Name AD Type Selected Groups Initiatives
ISO 27001-2013 International or National Standard 82 111 21
NIST SP 800-53 R4 International or National Standard 48 55 8
NIST Cybersecurity Framework International or National Standard 38 5 2
EU General Data Protection Regulation (GDPR) Regulation or Statute 35 73 4
NIST SP 800-53 R4 Moderate Impact International or National Standard 35 27 6
PCI DSS Requirements and Security Assessment Procedures Contractual Obligation 35 79 9
NIST SP 800-53 R4 High Impact International or National Standard 33 85 4
AICPA Reporting on Controls at a Service Organization SOC-2 Safe Harbor 32 47 5
NIST SP 800-53 R4 Low Impact International or National Standard 32 22 4
NIST SP 800-53 International or National Standard 26 9 3
Sarbanes Oxley SOX Regulation or Statute 26 79 16
ISO/IEC 27002:2013(E) International or National Standard 24 87 17
NIST SP 800-171 International or National Standard 21 4 1
HIPAA Bill or Act 19 46 8
CobiT Safe Harbor 16 91 6
NIST Framework for Improving Critical Infrastructure Cybersecurity International or National Standard 16 17 7
Red Book (Condensed) International or National Standard 16 1 1
FedRAMP Baseline Security Controls Audit Guideline 15 43 5
HIPAA Electronic Health Record Technology Regulation or Statute 15 7 3
ISO 27002 International or National Standard 15 11 7
CIS 20 Critical Security Controls Best Practice Guideline 14 6 2
ISO 31000 R 2009 International or National Standard 13 87 4
ISO 9001:2015 International or National Standard 13 1 1
NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations International or National Standard 13 1 2
CSIS 20 Critical Security Controls Best Practice Guideline 12 84 4
23 NYCRR 500 Regulation or Statute 11 0 6
45 CFR Part 164 Regulation or Statute 11 13 6
HIPAA HCFA Best Practice Guideline 11 18 2
ISO/IEC 27017:2015(E) Self-Regulatory Body Requirement 11 1 1
Framework for Improving Critical Infrastructure Cybersecurity International or National Standard 10 0 0
NIST 800-53A International or National Standard 10 6 3
NIST SP 800 66 Safe Harbor 10 8 5
SSAE No. 16 Reporting on Controls at a Service Organization SOC-1 Safe Harbor 9 11 3
Gramm Leach Bliley Bill or Act 8 12 10
ISO 20000-1 2nd Ed International or National Standard 8 43 4
PCI DSS 3.0 Requirements Self-Regulatory Body Requirement 8 19 6
Australian Government Information Security Manual Controls International or National Standard 7 6 3
Cloud Controls Matrix, Version 3.0 Self-Regulatory Body Requirement 7 6 1
COBIT 5 Enabling Processes: Basics Safe Harbor 7 3 0
Generally Accepted Privacy Principles Best Practice Guideline 7 4 0
ISO 27005 R 2011 International or National Standard 7 11 6
ISO 31000:2018 International or National Standard 7 0 0
Shared Assessments SIG - A. Risk Management Audit Guideline 7 7 3
Standards for Safeguarding Customer Information Model Regulation, NAIC MDL-673 Best Practice Guideline 7 0 0
21 CFR Part 11 Regulation or Statute 6 5 1
AICPA Trust Services Principles and Criteria Self-Regulatory Body Requirement 6 4 1
Australia Privacy Amendment Act Regulation or Statute 6 14 6
CIS Controls V7 Best Practice Guideline 6 0 0
Cloud Security Alliance CCM V1.3 Best Practice Guideline 6 12 6
EU 8th Directive Regulation or Statute 6 12 6