HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(1)(i): Security Management Process (Standard)

Implement policies and procedures to prevent, detect, contain, and correct security violations. NIST recommends establishing an enterprise security governance program with defined roles and risk-based decision making.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 84 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 7 controls

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.4 CC7.4 Responding to security incidents

ISO 27701:2019 · 6 controls

  • 5.4.1 Actions to address risks and opportunities
  • 5.6.2 Information security risk assessment
  • 5.8.1 Nonconformity and corrective action
  • 6.13.1 Management of information security incidents and improvements
  • 6.3 Organization of information security
  • 6.9.1 Operational procedures and responsibilities
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-RS.MI-01 Incidents are contained
  • NIST-CSF-RS.MI-02 Incidents are eradicated

CIS Controls v8 · 5 controls

  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-8.1 Establish and Maintain an Audit Log Management Process

ISO 22301:2019 · 5 controls

NIST SP 800-53 Rev 5 · 5 controls

PCI DSS 4.0 · 5 controls

  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 6.3.3 6.3.3 Timely installation of security patches

APRA CPS 234 · 4 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-19 Information Security Policy Framework
  • CPS234-21 Implementation of Information Security Controls
  • CPS234-30 Detection and Response Mechanisms

ISO 27001:2022 · 4 controls

  • 5.1 Policies for information security
  • 5.2 Information security roles and responsibilities
  • 5.24 Information security incident management planning and preparation 
  • 5.36 Compliance with policies, rules and standards for information security

ISO 27002:2022 · 4 controls

  • 5.1 Policies for information security
  • 5.2 Information security roles and responsibilities
  • 5.24 Information security incident management planning and preparation
  • 5.35 Independent review of information security
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-15 Operational Risk Elements of the Risk Management Framework
  • CPS230-24 Design and Embedding of Internal Controls

FedRAMP High · 3 controls

  • IR-4 Incident Handling
  • PL-1 Policy and Procedures
  • RA-1 Policy and Procedures

FedRAMP Moderate · 3 controls

  • IR-4 Incident Handling
  • PL-1 Policy and Procedures
  • RA-1 Policy and Procedures

NIST SP 800-171 Rev 3 · 3 controls

  • SEC01-BP03 Identify and validate control objectives
  • SEC01-BP06 Automate deployment of standard security controls

C5 (Germany) · 2 controls

  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-2 Enterprise Risk Management and Governance Category

NIST SP 800-161 Rev 1 · 2 controls

  • E8-APP-ML2 Application Control (ML2)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure

APPI · 1 control

  • CPS220-04 Maintenance of a Risk Management Framework
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • ASBv3-GS-5 Define and implement security posture management strategy

CMMC 2.0 · 1 control

NIST SP 800-172 · 1 control

  • 3.6.2e Establish and Maintain a Cyber Incident Response Team

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(1)(i) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 84 it maps to, and the evidence behind each claim, over MCP and REST.