Skip to content

Monthly Selected Authority Documents - March, 2023

Here is a list of the 50 most selected Authority Documents in the Common Controls Hub this past...

Here is a list of the 50 most selected Authority Documents in the Common Controls Hub this past month. We also list how many groups each Authority Document has been assigned to and how many initiatives it has been assigned to.

 

AD Common Name AD Type Selected Groups Initiatives
ISO/IEC 27001:2022 International or National Standard 46 5 3
NIST SP 800-53 R5 International or National Standard 46 26 14
NIST CSF 1.1 International or National Standard 43 49 22
EU General Data Protection Regulation (GDPR) Regulation or Statute 35 175 16
ISO/IEC 27002:2022 International or National Standard 32 3 5
PCI DSS Defined Approach Requirements, Version 4.0 International or National Standard 31 8 3
ISO 27001-2013 International or National Standard 30 205 19
CIS Controls, V8 Best Practice Guideline 29 9 8
Sarbanes-Oxley Act of 2002 Bill or Act 18 5 6
PCI DSS Defined Approach Testing Procedures, Version 4.0 International or National Standard 17 6 4
PCI DSS v3.2.1 Contractual Obligation 17 8 4
ISO/IEC 27701:2019 International or National Standard 16 18 8
NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations International or National Standard 16 11 8
23 NYCRR 500 Regulation or Statute 13 17 3
California Privacy Rights Act (CPRA) Bill or Act 13 2 1
hipaa security rule Regulation or Statute 13 5 1
ISO/IEC 27017:2015(E) Self-Regulatory Body Requirement 13 21 10
NIST CSF 1.0 International or National Standard 13 11 2
Cloud Controls Matrix, v4.0 Self-Regulatory Body Requirement 12 3 0
ISO 27002 International or National Standard 12 8 2
PCI DSS v4.0 SAQ D Merchants Contractual Obligation 12 1 0
SSAE No. 16 Reporting on Controls at a Service Organization SOC-1 Safe Harbor 12 9 3
ISO/IEC 27002:2013(E) International or National Standard 11 144 13
NIST Privacy Framework International or National Standard 11 15 7
TSP Section 100: 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy Self-Regulatory Body Requirement 11 4 2
AICPA Reporting on Controls at a Service Organization SOC-2 Safe Harbor 10 144 4
BSI Cloud Computing Compliance Controls Catalogue (C5) Best Practice Guideline 10 18 4
California Consumer Privacy Act of 2018 Bill or Act 10 44 1
CobiT Safe Harbor 10 167 1
HIPAA Bill or Act 10 10 4
NIST SP 800-37r2 International or National Standard 10 13 5
NIST SP 800-53 International or National Standard 9 17 1
BSI-Standard 100-2 International or National Standard 8 9 0
CMMC Level 2, v2.0 Best Practice Guideline 8 7 6
EBA/GL/2019/04 Regulation or Statute 8 13 0
Gramm Leach Bliley Bill or Act 8 3 0
NIST SP 800-39 International or National Standard 8 11 6
NIST SP 800-53 R4 International or National Standard 8 5 3
Australia Privacy Amendment Act Regulation or Statute 7 12 0
Control Baselines for Information Systems and Organizations, NIST Special Publication 800-53B, High Impact Baseline, October 2020 International or National Standard 7 10 8
Control Baselines for Information Systems and Organizations, NIST Special Publication 800-53B, Low Impact Baseline, October 2020 International or National Standard 7 9 5
COSO Enterprise Risk Management (2017) Best Practice Guideline 7 17 9
HIPAA Electronic Health Record Technology Regulation or Statute 7 2 1
HIPAA HCFA Best Practice Guideline 7 3 2
ISO/IEC 27018:2019 International or National Standard 7 1 1
NIST SP 800 66 Safe Harbor 7 31 1
NIST SP 800-171 International or National Standard 7 4 2
PCI DSS v4.0 SAQ A Self-Regulatory Body Requirement 7 0 0
SOC2 Safe Harbor 7 5 0
AICPA Trust Services Principles and Criteria Self-Regulatory Body Requirement 6 10 1