Australia My Health Records Act 2012
Security and Access

Australia My Health Records Act 2012 MYHR-SEC-3: Audit logging and access monitoring

Log and monitor access to and activity in the My Health Record system to detect and investigate unauthorised access.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 76 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 7 controls

SOC 2 · 6 controls

  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-P6.2 P6.2 Record of authorised disclosures
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches

FedRAMP High · 5 controls

  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-6 Audit Record Review, Analysis, and Reporting
  • IR-5 Incident Monitoring

FedRAMP Moderate · 5 controls

  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-6 Audit Record Review, Analysis, and Reporting
  • IR-5 Incident Monitoring

HIPAA Security Rule · 5 controls

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • NIST-CSF-RS.MA-02 Incident reports are triaged and validated

NIST SP 800-66 Rev 2 · 5 controls

  • ASBv3-LT-2 Enable threat detection for identity and access management
  • DP-2 Monitor anomalies and threats targeting sensitive data
  • LT-3 Enable logging for security investigation
  • LT-5 Centralize security log management and analysis

C5 (Germany) · 4 controls

  • C5-IDM-06 Privileged access rights
  • C5-OPS-13 Logging and Monitoring - Identification of Events
  • C5-OPS-14 Logging and Monitoring - Storage of the Logging Data
  • C5-OPS-15 Logging and Monitoring - Accountability

CIS Controls v8 · 4 controls

  • CIS-3.14 Log Sensitive Data Access
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.2 Collect Audit Logs

ISO 27001:2022 · 4 controls

  • 5.25 Assessment and decision on information security events
  • 5.28 Collection of evidence
  • 8.15 Logging
  • 8.16 Monitoring activities

ISO 27002:2022 · 4 controls

  • 5.25 Assessment and decision on information security events
  • 5.28 Collection of evidence
  • 8.15 Logging
  • 8.16 Monitoring activities

NIST SP 800-161 Rev 1 · 3 controls

APPI · 2 controls

  • APPI-A23 Security Control Measures
  • APPI-A29 Records When Providing Personal Data to a Third Party

GDPR · 2 controls

  • GDPR-Art.32 Security of processing
  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority
  • CBPR-PR-32 Detection, prevention and response measures

APRA CPS 234 · 1 control

  • CPS234-30 Detection and Response Mechanisms
  • APP-11 APP 11 - Security of personal information

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Security and Access

You are reading one control. How much of Australia My Health Records Act 2012 have you already done?

Australia My Health Records Act 2012 MYHR-SEC-3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Australia My Health Records Act 2012 your existing evidence covers. Hold FedRAMP Moderate and 9 of 40 Australia My Health Records Act 2012 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 76 it maps to, and the evidence behind each claim, over MCP and REST.