Skip to main content
more options

Search This Site

  • Ethical Conduct and Compliance Hotline
  • My Audit
  • Home
    • University Audit Office Charter
    • Board of Trustees Audit, Risk, and Compliance Committee Operating Principles and Practices
  • Services
    • Assurance
    • Ethical Conduct and Compliance Hotline
  • Contact
    • Ithaca Office
    • Weill Cornell Medicine Office
    • Organizational Chart
  • Resources
    • External Regulations and Guidance
    • University Policies
  Cornell University
University Audit Office
  • Home
    • University Audit Office Charter
    • Board of Trustees Audit, Risk, and Compliance Committee Operating Principles and Practices
  • Services
    • Assurance
    • Ethical Conduct and Compliance Hotline
  • Contact
    • Ithaca Office
    • Weill Cornell Medicine Office
    • Organizational Chart
  • Resources
    • External Regulations and Guidance
    • University Policies
Resources
HomeResourcesExternal Regulations and Guidance

External Regulations and Guidance

Control Frameworks:

Control Objectives for Information and Related Technologies (COBIT)

National Institute of Standards and Technology (NIST) Special Publication 800-53

Committee of Sponsoring Organizations of the Treadway Commission (COSO)

SANS Institute CIS Critical Security Controls

Regulations and Related Guidance:

Controlled Technical Information (CTI)

Controlled Unclassified Information (CUI)

Family Educational Rights and Privacy Act (FERPA)

Federal Information Security Management Act (FISMA)

Federal Information Processing Standards (FIPS) for Security Categorization

Gramm Leach Bliley Act (GLBA)

GSA Privacy Program

Health Information Portability and Accountability Act (HIPAA)

National Institute of Standards and Technology (NIST)

New York State Technology Law

Payment Card Industry (PCI) Standards

Privacy Act of 1974

Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance)

Bylaws, Charters, and Policies

  • Board of Trustees
  • Cornell University Bylaws
  • Weill Cornell Medicine (WCM) Governance
  • University Audit Office Charter
  • University Policy Library

Office of the Chief Risk Officer

  • Chief Risk Officer
  • Compliance & Privacy Office, WCM
  • Compliance Office, Ithaca
  • Privacy Office, Ithaca
  • University Hotline

Other Information

  • Alliance for Diversity and Inclusion
  • Campus Alerts, Cornell Tech
  • Campus Alerts, Ithaca
  • Campus Alerts, WCM
  • Careers at Cornell University

Cornell University©2025University PrivacyWeb Accessibility Assistance