Discover the latest Authority Documents added to our library in November 2024 and upcoming releases for April/May 2025, covering cybersecurity, AI, and financial regulations.
May 9, 2025
| Name | AD ID |
|---|---|
| Draft RTS on Threat-Led Penetration Testing | 4015 |
| Nevada Revised Statutes Title 43 Chapter 480 Section 935, Political subdivisions required to adopt and maintain cybersecurity incident response plan; plan to be filed with Office; requirements for plan; confidentiality; exceptions; regulations | 4027 |
| National Cyber Security Centre Cyber Assessment Framework, v3.2 | 3994 |
| NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile | 3990 |
| StateRAMP Baseline Controls for Authorization for Moderate Impact Level | 4003 |
| New York Codes, Rules and Regulations, Title 10 Section 405.46 - Hospital Cybersecurity Requirements | 4032 |
| StateRAMP Baseline Controls for Authorization for Low Impact Level | 4002 |
| StateRAMP Ready Minimum Mandatory Requirements for Moderate/High Impact Level | 4005 |
| StateRAMP Ready Minimum Mandatory Requirements for Low Impact Level | 4040 |
| Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs), Version 1.0 | 4031 |
| ISO 42001:2023, Information technology — Artificial intelligence — Management system, First Edition | 4039 |
| FFIEC Information Technology Examination Handbook - Information Security, September 2016 | 4024 |
| Cybersecurity Maturity Model Certification (CMMC) Model Level 1 | 4042 |
| Cybersecurity Maturity Model Certification (CMMC) Model Level 2 | 4043 |
| Cybersecurity Maturity Model Certification (CMMC) Model Level 3 | 4044 |
| Circular 10/2017 (BA) Supervisory Requirements for IT in Financial Institutions (BAIT) in the version of 16.08.2021 | 4030 |
| Personal Information Protection and Electronic Documents Act S.C. 2000, c. 5, Last amended on August 19, 2024 | 4045 |
| Kentucky Revised Statutes, Title XXV, Chapter 304, Subtitle 3, Sections 304.3-750 thru 304.3-768, Data Security | 4048 |
| Insurance Information and Privacy Protection Model Act, NAIC MDL-670, October 1992 | 4041 |
| Rhode Island General Laws, Title 27, Chapter 27-1, Sections 46 thru 47 and Chapter 27-2, Sections 29 thru 30, Insurance Data Security | 4052 |
| Illinois Compiled Statutes, Chapter 215, ILCS 215/ Insurance Data Security Law | 4047 |
| Code of Maryland Insurance, Title 33, Insurance Data Security | 4049 |
| Oklahoma Statutes, Title 36, Article 6b, Insurance Data Security Act | 4050 |
| Vermont Statutes Annotated, Title 8, Chapter 129, Section 4728, Insurance data security | 4053 |
| Pennsylvania Consolidated Statutes, Title 40, Chapter 45, Insurance Data Security | 4051 |
| GUERNSEY FINANCIAL SERVICES COMMISSION CYBER SECURITY RULES, 2021 | 4057 |
| Pipeline Security Guidelines, March 2018 (with Change 1 (April 2021)) | 4054 |
| Cybersecurity Maturity Model Certification (CMMC) Assessment Guide, Level 1, Version 2.13 | 4059 |
| ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system, First Edition | 4062 |
| NIST SP 800-171A Rev. 3 Assessing Security Requirements for Controlled Unclassified Information | 4056 |
| Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU (recast) | 4046 |
| NIST SP 800-172A, Assessing Enhanced Security Requirements for Controlled Unclassified Information | 4058 |
| Cybersecurity Maturity Model Certification (CMMC) Assessment Guide, Level 3, Version 2.13 | 4061 |
| NIST SP 800-83 Rev 1, Guide to Malware Incident Prevention and Handling for Desktops and Laptops | 4065 |
| Cybersecurity Maturity Model Certification (CMMC) Assessment Guide, Level 2, Version 2.13 | 4060 |
| Self-Assessment Questionnaire SPoC and Attestation of Compliance For use with PCI DSS Version 4.0.1 | 4089 |
| Self-Assessment Questionnaire A and Attestation of Compliance For use with PCI DSS Version 4.0.1, Revision 1 | 4080 |
| Self-Assessment Questionnaire B and Attestation of Compliance For use with PCI DSS Version 4.0.1 | 4082 |
| Self-Assessment Questionnaire B-IP and Attestation of Compliance For use with PCI DSS Version 4.0.1 | 4083 |
| Self-Assessment Questionnaire C and Attestation of Compliance For use with PCI DSS Version 4.0.1 | 4084 |
| Self-Assessment Questionnaire A-EP and Attestation of Compliance For use with PCI DSS Version 4.0.1 | 4081 |
| Self-Assessment Questionnaire C-VT and Attestation of Compliance For use with PCI DSS Version 4.0.1 | 4085 |
| Self-Assessment Questionnaire D for Merchants and Attestation of Compliance For use with PCI DSS Version 4.0.1 | 4086 |
| Self-Assessment Questionnaire D for Service Providers and Attestation of Compliance For use with PCI DSS Version 4.0.1, Revision 2 | 4087 |
| Information Security Assessment, v6.0.3 | 4070 |
| Self-Assessment Questionnaire P2PE and Attestation of Compliance For use with PCI DSS Version 4.0.1 | 4088 |
| Cyber Essentials: Requirements for IT Infrastructure, v3.2 | 4093 |
| Cyber Essentials Self-Assessment Preparation Booklet, Version 15.1 | 4095 |
| ISO 13485:2016, Medical devices — Quality management systems — Requirements for regulatory purposes, Third edition | 4063 |
| Name | AD ID |
|---|---|
| ISO 37001:2025, Anti-bribery management systems — Requirements with guidance for use, Second edition | 4064 |
| NEI 08-09 [Rev. 7], Cyber Security Plan for Nuclear Power Reactors | 4067 |
| MPA Content Security Best Practices, v5.3 | 4069 |
| NIST SP 800-82r3, Guide to Operational Technology (OT) Security with Operational Technology Overlay, High Impact Baseline | 4073 |
| NIST SP 800-82r3, Guide to Operational Technology (OT) Security with Operational Technology Overlay, Moderate Impact Baseline |