HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(1)(ii)(B): Risk Management (Required)

Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. NIST recommends prioritized treatment plans, residual risk acceptance by leadership, and continuous monitoring tied to NIST SP 800-137.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 134 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 14 controls

  • 1.2.6 1.2.6 Security features for insecure services in use
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.2.4 2.2.4 Only necessary functionality enabled
  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.2 6.3.2 Inventory of bespoke software and components

ISO 27701:2019 · 12 controls

  • 5.4 Planning
  • 5.4.1 Actions to address risks and opportunities
  • 5.6.2 Information security risk assessment
  • 5.6.3 Information security risk treatment
  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 6.10.1 Network security management
  • 6.11 Systems acquisition, development and maintenance
  • 6.11.1 Security requirements of information systems
  • 6.9 Operations security
  • 7.4 Privacy by design and privacy by default
  • 8.2 Conditions for collection and processing
  • 8.4 Privacy by design and privacy by default

CIS Controls v8 · 9 controls

  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-7.7 Remediate Detected Vulnerabilities

NIST SP 800-53 Rev 5 · 9 controls

ISO 27001:2022 · 7 controls

  • 5.25 Assessment and decision on information security events
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 5.7 Threat intelligence
  • 8.16 Monitoring activities
  • 8.27 Secure system architecture and engineering principles
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
  • NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated

ISO 22301:2019 · 6 controls

  • 6.1 Actions to address risks and opportunities
  • 6.1.1 Determining risks and opportunities
  • 6.1.2 Addressing risks and opportunities
  • 8.1 Operational planning and control
  • 8.2 Business impact analysis and risk assessment
  • 8.2.3 Risk assessment

ISO 27002:2022 · 6 controls

  • 5.24 Information security incident management planning and preparation
  • 5.34 Privacy and protection of PII
  • 5.7 Threat intelligence
  • 8.16 Monitoring activities
  • 8.26 Application security requirements
  • 8.8 Management of technical vulnerabilities

CMMC 2.0 · 5 controls

NIST SP 800-161 Rev 1 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption

APRA CPS 234 · 4 controls

  • CPS234-15 Information Security Capability
  • CPS234-21 Implementation of Information Security Controls
  • CPS234-28 Escalation of Unremediated Testing Deficiencies
  • CPS234-P17 Active Maintenance of Capability Against Change
  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-17 Enterprise Technology Risk Assessment
  • CFTC-SS-2 Enterprise Risk Management and Governance Category
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies

FedRAMP High · 4 controls

  • CA-5 Plan of Action and Milestones
  • CA-7 Continuous Monitoring
  • RA-3 Risk Assessment
  • SI-2 Flaw Remediation

FedRAMP Moderate · 4 controls

  • CA-5 Plan of Action and Milestones
  • CA-7 Continuous Monitoring
  • RA-3 Risk Assessment
  • SI-2 Flaw Remediation
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-24 Design and Embedding of Internal Controls
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses
  • SEC01-BP07 Identify threats and prioritize mitigations using a threat model
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • SEC06-BP01 Perform vulnerability management

C5 (Germany) · 3 controls

  • C5-OIS-06 Risk Management Policy
  • C5-OIS-07 Application of the Risk Management Policy
  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept

NIST SP 800-171 Rev 3 · 3 controls

ACSC Essential Eight · 2 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • ANSSI-HYG-41 Conduct a Formal Risk Analysis
  • AUCDR-IS-4 Formal vulnerability management program
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • CPS220-P35 Required Content of Risk Management Policies and Procedures
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities

ISO/IEC 42001:2023 · 1 control

  • 8.3 AI risk treatment

NIST SP 800-172 · 1 control

  • 3.11.4e Security Solution Rationale Document

NIST SP 800-218 · 1 control

UK Cyber Essentials · 1 control

  • CE-FW.1 Boundary Firewalls Deployed

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(1)(ii)(B) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 134 it maps to, and the evidence behind each claim, over MCP and REST.