News

4 new Authority Documents have been added to the UCF

April 13, 2020 | Weekly Updates

FFIEC Business Continuity Planning (BCP) IT Examination Handbook
AD ID: 3105
Status: Released
Availability: Free
Citation Format: Rule (Defined Rules)
Document Type: FFIEC Business Continuity Planning (BCP) IT Examination Handbook
Originator: US Federal Financial Institutions Examination Council (FFIEC)
Parent Category: North America
Effective Date: 2019-11-01
Language: eng

Click here to launch this Authority Document in the Common Controls Hub

This Authority Document has 758 citations mapped to 287 UCF Common Control IDs. The document as a whole was last reviewed and released on 2020-04-08.

Percent (%) of Citations with multiple mandates: 23.7%

Percent (%) of terms that were non-standard: 11.00% The number of non-standard terms doesn't affect UCF users as the UCF team have already mapped those terms to standard terms in the Compliance Dictionary.

Percent (%) of terms mapped into the AD's glossary: 0.1% Primary verbs and nouns not mapped into an AD's glossary can point to the AD's authors not paying attention to the definitions of their terms.

Percent (%) of terms where fewer than 5 other ADs referenced the term: 29.2% Any term in this category is not very widely used by the rest of the compliance community and therefore will more than likely need to be further investigated for any implications it might bring.

Percent (%) of mandates where only 1 to 5 other ADs mapped to the Common Control: 100% Mandates that aren't widely called for will take longer to implement than mandates that are more familiar.

Number of mandates where 0 other ADs mapped to the Common Control: 1.2% These mandates are only called for by this AD, making them particularly thorny to implement, as this AD is the "lone wolf" in asking for them to be followed.


Hong Kong Monetary Authority Supervisory Policy Manual SA-2 Outsourcing
AD ID: 3151
Status: Released
Availability: Free
Citation Format: ¶ (Para and Page) with Section Titles
Document Type: Hong Kong Monetary Authority Supervisory Policy Manual SA-2 Outsourcing
Originator: Hong Kong Monetary Authority
Parent Category: Asia
Effective Date: 2001-12-28
Language: eng

Click here to launch this Authority Document in the Common Controls Hub

This Authority Document has 81 citations mapped to 0 UCF Common Control IDs. The document as a whole was last reviewed and released on 2020-04-10.

Percent (%) of Citations with multiple mandates: 33.3%

Percent (%) of terms that were non-standard: 9.80% The number of non-standard terms doesn't affect UCF users as the UCF team have already mapped those terms to standard terms in the Compliance Dictionary.

Percent (%) of terms mapped into the AD's glossary: 0% Primary verbs and nouns not mapped into an AD's glossary can point to the AD's authors not paying attention to the definitions of their terms.

Percent (%) of terms where fewer than 5 other ADs referenced the term: 18.5% Any term in this category is not very widely used by the rest of the compliance community and therefore will more than likely need to be further investigated for any implications it might bring.

Percent (%) of mandates where only 1 to 5 other ADs mapped to the Common Control: 0% Mandates that aren't widely called for will take longer to implement than mandates that are more familiar.

Number of mandates where 0 other ADs mapped to the Common Control: 1.2% These mandates are only called for by this AD, making them particularly thorny to implement, as this AD is the "lone wolf" in asking for them to be followed.


Pandemic Response Planning Policy
AD ID: 3160
Status: Released
Availability: Free
Citation Format: ¶ (Para and Page) with Section Titles
Document Type: Pandemic Response Planning Policy
Originator: SANS Institute
Parent Category: Security and Privacy Organizations
Effective Date: 2020-03-01
Language: eng

Click here to launch this Authority Document in the Common Controls Hub

This Authority Document has 51 citations mapped to 28 UCF Common Control IDs. The document as a whole was last reviewed and released on 2020-04-06.

Percent (%) of Citations with multiple mandates: 11.4%

Percent (%) of terms that were non-standard: 16.80% The number of non-standard terms doesn't affect UCF users as the UCF team have already mapped those terms to standard terms in the Compliance Dictionary.

Percent (%) of terms mapped into the AD's glossary: 0% Primary verbs and nouns not mapped into an AD's glossary can point to the AD's authors not paying attention to the definitions of their terms.

Percent (%) of terms where fewer than 5 other ADs referenced the term: 23.5% Any term in this category is not very widely used by the rest of the compliance community and therefore will more than likely need to be further investigated for any implications it might bring.

Percent (%) of mandates where only 1 to 5 other ADs mapped to the Common Control: 0% Mandates that aren't widely called for will take longer to implement than mandates that are more familiar.

Number of mandates where 0 other ADs mapped to the Common Control: 33.3% These mandates are only called for by this AD, making them particularly thorny to implement, as this AD is the "lone wolf" in asking for them to be followed.


Cybersecurity Maturity Model Certification
AD ID: 3166
Status: Released
Availability: Free
Citation Format: Control:
Document Type: Cybersecurity Maturity Model Certification
Originator: US Department of Defense
Parent Category: North America
Effective Date: 2020-04-07
Language: eng

Click here to launch this Authority Document in the Common Controls Hub

This Authority Document has 199 citations mapped to 0 UCF Common Control IDs. The document as a whole was last reviewed and released on 2020-04-08.

Percent (%) of Citations with multiple mandates: 20.5%

Percent (%) of terms that were non-standard: 100.00% The number of non-standard terms doesn't affect UCF users as the UCF team have already mapped those terms to standard terms in the Compliance Dictionary.

Percent (%) of terms mapped into the AD's glossary: 0% Primary verbs and nouns not mapped into an AD's glossary can point to the AD's authors not paying attention to the definitions of their terms.

Percent (%) of terms where fewer than 5 other ADs referenced the term: 6.5% Any term in this category is not very widely used by the rest of the compliance community and therefore will more than likely need to be further investigated for any implications it might bring.

Percent (%) of mandates where only 1 to 5 other ADs mapped to the Common Control: 0% Mandates that aren't widely called for will take longer to implement than mandates that are more familiar.

Number of mandates where 0 other ADs mapped to the Common Control: 0% These mandates are only called for by this AD, making them particularly thorny to implement, as this AD is the "lone wolf" in asking for them to be followed.