1. Shared Assessments, Certified Third Party Risk Professional (CTPRP) Body of Knowledge, Domain 1: TPRM Program Governance. This domain establishes the foundational concepts of governance, including the hierarchy and nature of laws, regulations, and standards that drive a risk program.
2. NIST Special Publication 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations, Appendix F, Page F-1. The document distinguishes between federal laws, executive orders, directives, policies, regulations, and standards, clarifying their respective roles and authority.