Monthly Selected Authority Documents November, 2024
Here is a list of the 50 most selected Authority Documents in the Common Controls Hub this past month. We also list how many groups each Authority Document has been assigned to and how many initiatives it has been assigned to.
AD_NameAD_idAD_typeselectedgroupsinitiativesISO/IEC 27001:20223567International or National Standard42124NIST CSF 2.03789International or National Standard3684ISO/IEC 27002:20223430International or National Standard301410NIST SP 800-53 R53241International or National Standard213318Digital Operational Resilience Act3668Regulations2052NIST SP 800-53 Revision 5.1.13687International or National Standard1622CIS Controls Version 8.13955Best Practice Guideline1500EU General Data Protection Regulation (GDPR)2802Regulation or Statute1519021PCI DSS Defined Approach Testing Procedures v4.0.13988International or National Standard1500ISO/IEC 27701:20193020International or National Standard132010NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations3134International or National Standard131910CMMC Level 2, v2.03427Best Practice Guideline12136HIPAA3201Bill or Act12114ISO/IEC 27017:2015(E)2838Self-Regulatory Body Requirement122511SOC 2®, 20223647Audit Guideline1230CobiT102Safe Harbor111682PCI DSS Defined Approach Requirements v4.0.13987International or National Standard1100CIS Controls, V83323Best Practice Guideline10159CMMC Level 1, v2.03426Best Practice Guideline10115NIST CSF 1.12934International or National Standard106623Sarbanes-Oxley Act of 20023296Bill or Act1076Trust Services Criteria (with Revised Points of Focus – 2022)3609Self-Regulatory Body Requirement109345 CFR Part 160986Regulation or Statute99445 CFR Part 162985Regulation or Statute984Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, 14 December, 20223714Regulatory Directive or Guidance974PCI DSS Defined Approach Requirements, Version 4.03444International or National Standard9176Delegated regulation specifying fees for the critical ICT third-party service providers in the financial sector3979Regulations800HIPAA Electronic Health Record Technology3208Regulation or Statute832HIPAA HCFA3200Best Practice Guideline854HIPAA Security and Privacy Rule3986Regulations820hipaa security rule3204Regulation or Statute872ISO 9001:20152942International or National Standard8236NIST 800-171 Rev 33946International or National Standard810NIST AI 100-13591Best Practice Guideline810Regulations specifying criteria (policy) for the critical ICT third-party service providers in the financial sector3977Regulations800RTS specifying criteria regarding ICT risk management3975Regulations800RTS specifying the criteria for classification of ICT-related incidents3976Regulations800Cloud Controls Matrix, v4.03303Self-Regulatory Body Requirement781COBIT 20193009Safe Harbor792ISO 27001-20131367International or National Standard722223Artificial Intelligence Act3972Regulations600ISO 22301- Societal Security - Business Continuity Management Systems - Requirements1423International or National Standard6201NIST SP 800-392428International or National Standard6227NIST SP 800-66r23960International or National Standard610PCI DSS v4.0 SAQ D Merchants3464Contractual Obligation698Security and Privacy Controls for Federal Information Systems and Organizations, NIST SP 800-53, Low Impact Baseline, Revision 43242International or National Standard650SSAE No. 16 Reporting on Controls at a Service Organization SOC-11108Safe Harbor694BSI Cloud Computing Compliance Controls Catalogue (C5)3007Best Practice Guideline5184California Consumer Privacy Act of 20182957Bill or Act5452California Privacy Rights Act (CPRA)3290Bill or Act553{{ include_custom_fonts({"Aeonik":["Regular","Bold"]}) }}
Request a demo of ControlSight and see how Unified Compliance connects mandates, policies, and controls into one living fabric.