|
Sarbanes-Oxley Act (SOX)
|
The Sarbanes-Oxley Act is a U.S. corporate accountability law focused on financial reporting and internal controls.
SOX is not a writing style standard; it affects documentation through control evidence, change control, approvals, records retention, audit trails, and traceability of financial-system procedures.
Additional Resources:
|
|
| |
|
ISO/IEC 27001
|
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS).
It affects documentation through security policies, risk treatment plans, procedures, control evidence, statement of applicability, internal audits, and continual improvement.
Additional Resources:
|
|
| |
|
NIST Cybersecurity Framework (CSF)
|
The NIST Cybersecurity Framework (CSF) is a voluntary framework for managing and communicating cybersecurity risk.
It influences documentation for profiles, governance outcomes, risk management, policies, procedures, metrics, and executive cybersecurity communication.
Additional Resources:
|
|
| |
|
NIST SP 800-53
|
NIST SP 800-53 provides a catalog of security and privacy controls for information systems and organizations.
It drives system security documentation, control implementation statements, assessment evidence, policies, procedures, plans, and authorization artifacts.
Additional Resources:
|
|
| |
|
NIST SP 800-171
|
NIST SP 800-171 defines requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.
It affects contractor documentation through security plans, policies, procedures, evidence of implementation, assessments, and CUI handling instructions.
Additional Resources:
|
|
| |
|
FedRAMP
|
FedRAMP is the U.S. governmentwide program for standardized security assessment and authorization of cloud products and services.
It affects cloud security documentation, system security plans, control implementation evidence, policies, procedures, continuous monitoring, and authorization packages.
Additional Resources:
|
|
| |
|
FISMA
|
FISMA establishes federal information-security program requirements and oversight expectations.
It influences federal system documentation, risk assessments, security plans, annual reporting, controls, incident response, and audit evidence.
Additional Resources:
|
|
| |
|
CMMC
|
CMMC is the DoD cybersecurity assessment program for defense contractors and subcontractors.
It affects documentation for CUI protection, control implementation, policies, procedures, evidence collection, assessment preparation, and supplier compliance.
Additional Resources:
|
|
| |
|
SOC 2
|
SOC 2 is an assurance reporting framework based on AICPA Trust Services Criteria.
It affects technical documentation through control descriptions, policies, procedures, evidence, service commitments, system boundaries, and audit-ready process records.
Additional Resources:
|
|
| |
|
PCI DSS
|
PCI DSS is the Payment Card Industry Data Security Standard.
It affects documentation for cardholder-data environments, security controls, procedures, network diagrams, access controls, logging, testing, and compliance evidence.
Additional Resources:
|
|
| |
|
Zero Trust Architecture - NIST SP 800-207
|
NIST SP 800-207 describes Zero Trust Architecture principles and deployment concepts.
It affects security documentation through identity, access, device, data-flow, policy-decision, monitoring, and architecture descriptions.
Additional Resources:
|
|
| |
|
HIPAA
|
HIPAA governs privacy and security protections for Protected Health Information (PHI) in healthcare contexts.
It affects documentation through Privacy Rule and Security Rule policies, Minimum Necessary procedures, Business Associate agreements, administrative safeguards, technical safeguards, and evidence of compliance.
Additional Resources:
|
|
| |
|
HITECH Act
|
The HITECH Act promoted health IT adoption and strengthened HIPAA privacy and security enforcement.
It affects documentation for breach notification, electronic health information exchange, security controls, enforcement evidence, and healthcare compliance procedures.
Additional Resources:
|
|
| |
|
CMS Documentation Requirements
|
CMS documentation requirements shape Medicare and Medicaid healthcare documentation expectations.
They affect complete, accurate, timely records, provider guidance, coverage documentation, audit support, fraud/waste/abuse controls, and beneficiary-facing communications.
Additional Resources:
|
|
| |
|
42 CFR Part 2
|
42 CFR Part 2 governs confidentiality of substance use disorder patient records.
It affects healthcare documentation through consent, disclosure limits, redisclosure notices, privacy procedures, system records, and careful handling of sensitive clinical information.
Additional Resources:
|
|
| |
|
21 CFR Part 11
|
21 CFR Part 11 defines FDA criteria for trustworthy electronic records and electronic signatures.
It affects regulated documentation through audit trails, validation, electronic signatures, access controls, record retention, and procedural evidence.
Additional Resources:
|
|
| |
|
GDPR
|
GDPR is the European Union's data protection and privacy regulation.
It affects documentation through privacy notices, lawful-basis records, consent language, data subject rights procedures, retention rules, records of processing, and breach communication.
Additional Resources:
|
|
| |
|
CCPA/CPRA
|
CCPA and CPRA establish California consumer privacy rights and implementing regulations.
They affect documentation through privacy notices, data-request procedures, opt-out language, retention disclosures, vendor terms, and evidence of privacy governance.
Additional Resources:
|
|
| |
|
S1000D
|
S1000D is an international specification for technical publications using a Common Source Database (CSDB).
It affects structured technical content through data modules, reuse, metadata, applicability, publication modules, controlled source content, and aerospace/defense maintenance information.
Additional Resources:
|
|
| |
|
MIL-STD-40051
|
MIL-STD-40051 establishes technical content, style, format, and functionality requirements for U.S. military technical manuals and IETMs.
It affects defense documentation through operator and maintenance instructions, warnings, procedural content, illustrated parts, troubleshooting, and publication structure.
Additional Resources:
|
|
| |
|
MIL-STD-961
|
MIL-STD-961 establishes format and content requirements for defense specifications and program-unique specifications.
It affects specification writing, amendments, notices, revisions, standard data, contractual deliverables, and controlled defense documentation.
Additional Resources:
|
|
| |
|
MIL-STD-882
|
MIL-STD-882 is the DoD standard practice for system safety.
It affects documentation through hazard analysis, risk acceptance, safety requirements, mitigation tracking, and evidence that hazards are identified and controlled.
Additional Resources:
|
|
| |
|
MIL-STD-1472
|
MIL-STD-1472 provides DoD human engineering and human factors design criteria.
It affects technical documentation by shaping human-centered requirements, usability expectations, labeling, controls, displays, warnings, and operator information.
Additional Resources:
|
|
| |
|
MIL-STD-38784
|
MIL-STD-38784 is a military technical-manual style and format standard for controlled defense documentation. It belongs in content governance and government/defense documentation standards rather than Legacy because it remains an active technical-manual reference and communicates current regulated-documentation context. Additional Resources:
|
|
| |
|
DoD Risk Management Framework (RMF)
|
DoDI 8510.01 establishes the cybersecurity Risk Management Framework for DoD systems.
It affects authorization documentation, assessment packages, system security plans, control evidence, risk decisions, continuous monitoring, and reciprocity records.
Additional Resources:
|
|
| |
|
DFARS Cybersecurity Requirements
|
DFARS cybersecurity clauses establish defense acquisition requirements tied to safeguarding covered defense information and cyber incident reporting.
They affect contractor documentation for CUI handling, supplier flow-downs, security implementation, incident reporting, and audit-ready compliance evidence.
Additional Resources:
|
|
| |
|
ANSI Z535
|
ANSI Z535 is a family of U.S. safety sign, label, color, and accident-prevention information standards.
It affects technical documentation through signal words, warning hierarchy, safety symbols, hazard statements, precautionary messages, labels, manuals, and product safety communication.
Additional Resources:
|
|
| |
|
OSHA Hazard Communication / GHS
|
OSHA Hazard Communication and the Globally Harmonized System (GHS) govern how chemical hazards are classified and communicated in workplace documentation.
The consolidated record covers safety data sheets, labels, pictograms, signal words, hazard statements, precautionary statements, training content, and procedural safety communication.
Additional Resources:
|
|
| |
|
ISO 9241 - Ergonomics of Human-System Interaction
|
ISO 9241 is a broad ergonomics and human-system interaction standards family covering usability, interaction principles, accessibility-related usability concerns, and human-centred design concepts. A separate ISO 9241-210 record was not created because the broader ISO 9241 record can represent the portfolio-relevant usability and human-centred design governance concepts without standards bloat. Additional Resources:
|
|
| |
|
DITA - Darwin Information Typing Architecture
|
DITA is an XML-based architecture for topic-based, structured authoring, content reuse, and technical-information delivery.
- Relevant to technical writing because it supports reusable topics, maps, conditional publishing, controlled information typing, and consistent enterprise documentation.
- It belongs here as a core structured-authoring capability and also under governance / standards.
Additional Resources:
|
|
| |
|
OpenAPI Specification
|
OpenAPI Specification is a structured API definition format for describing HTTP APIs, endpoints, operations, schemas, parameters, responses, authentication, and machine-readable API documentation. Additional Resources:
|
|
| |
|
JSON Schema
|
JSON Schema is a vocabulary for describing and validating JSON data structures, including object shapes, required properties, types, constraints, and machine-readable API or configuration contracts. Additional Resources:
|
|
| |
|
ITIL
|
ITIL is a widely used IT service-management framework.
It affects operational documentation through service catalogs, incident, change, problem, configuration, knowledge, runbook, SLA, and continual-improvement documentation.
Additional Resources:
|
|
| |
|
NIST AI Risk Management Framework (AI RMF)
|
The NIST AI Risk Management Framework helps organizations manage risks from AI systems.
It affects AI documentation through risk mapping, governance records, model and system documentation, transparency, evaluation evidence, monitoring, and responsible AI practices.
Additional Resources:
|
|
| |
|
ISO/IEC 42001 - AI Management System
|
ISO/IEC 42001 is a management-system standard for artificial intelligence.
It affects AI governance documentation through policies, objectives, risk controls, accountability, lifecycle records, supplier controls, assessments, and continuous improvement.
Additional Resources:
|
|
| |