Bibliography · auto-derived from course content · 6 modules

GRC and Compliance Fundamentals bibliography

18 unique peer-reviewed primary sources, deduplicated across 6 modules. Auto-generated from the course's actual references data, when the course adds a citation, this page updates automatically. The full DecipherU sourcing standard is at /academic-rigor.

Peer-reviewed journals · 1

  1. European Parliament and Council of the European Union (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2016/679/oj

Other primary sources · 16

  1. American Institute of Certified Public Accountants (2017). Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (TSP 100). AICPA. https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-servicesCited in 3 modules
  2. U.S. General Services Administration (2023). FedRAMP Rev. 5 Baselines. FedRAMP Program Management Office. https://www.fedramp.gov/rev5/baselines/
  3. Cloud Security Alliance (2021). Consensus Assessments Initiative Questionnaire (CAIQ) v4. Cloud Security Alliance. https://cloudsecurityalliance.org/research/cloud-controls-matrix
  4. Shared Assessments (2024). Standardized Information Gathering (SIG) Questionnaire (SIG Lite, SIG Core). Shared Assessments. https://sharedassessments.org/sig/
  5. Boyens, J., Smith, A., Bartol, N., Winkler, K., Holbrook, A., & Fallon, M. (2022). Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations (NIST SP 800-161 Rev. 1). National Institute of Standards and Technology. doi:10.6028/NIST.SP.800-161r1
  6. PCI Security Standards Council (2022). Payment Card Industry Data Security Standard (PCI DSS) v4.0. PCI Security Standards Council. https://www.pcisecuritystandards.org/document_library/
  7. Joint Task Force (2014). Assessing Security and Privacy Controls in Federal Information Systems and Organizations (NIST SP 800-53A Rev. 4). National Institute of Standards and Technology. doi:10.6028/NIST.SP.800-53Ar4Cited in 2 modules
  8. Joint Task Force (2018). Risk Management Framework for Information Systems and Organizations (NIST SP 800-37 Rev. 2). National Institute of Standards and Technology. doi:10.6028/NIST.SP.800-37r2Cited in 2 modules
  9. Joint Task Force (2020). Security and Privacy Controls for Information Systems and Organizations (NIST SP 800-53 Rev. 5). National Institute of Standards and Technology. doi:10.6028/NIST.SP.800-53r5
  10. ISC2 (2024). Cybersecurity Workforce Study 2024. International Information System Security Certification Consortium. https://www.isc2.org/research
  11. U.S. Department of Health and Human Services (2013). HIPAA Security Rule (45 CFR Parts 160, 164 Subparts A and C). U.S. Department of Health and Human Services. https://www.hhs.gov/hipaa/for-professionals/security/index.html
  12. U.S. Bureau of Labor Statistics (2024). Occupational Employment and Wage Statistics, May 2024: 15-1212 Information Security Analysts. U.S. Department of Labor. https://www.bls.gov/oes/current/oes151212.htm
  13. Stine, K., Kissel, R., Barker, W. C., Fahlsing, J., & Gulick, J. (2008). Guide for Mapping Types of Information and Information Systems to Security Categories (NIST SP 800-60 Vol. 1 Rev. 1). National Institute of Standards and Technology. doi:10.6028/NIST.SP.800-60v1r1
  14. National Institute of Standards and Technology (2004). Standards for Security Categorization of Federal Information and Information Systems (FIPS 199). National Institute of Standards and Technology. doi:10.6028/NIST.FIPS.199
  15. National Institute of Standards and Technology (2024). Cybersecurity Framework (CSF) 2.0. National Institute of Standards and Technology. doi:10.6028/NIST.CSWP.29
  16. U.S. Department of Health and Human Services Office for Civil Rights and the Office of the National Coordinator for Health Information Technology (2024). Security Risk Assessment Tool. HHS / ONC. https://www.healthit.gov/topic/privacy-security-and-hipaa/security-risk-assessment-tool

Export

Cite this bibliography in your own work

One-click copy of the entire bibliography in three formats. The same data, machine-readable, audit-ready.