HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(1)(ii)(B): Risk Management (Required)

Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. NIST recommends prioritized treatment plans, residual risk acceptance by leadership, and continuous monitoring tied to NIST SP 800-137.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 146 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 14 controls

  • 1.2.6 Security features for insecure services defined
  • 11.3.1 Internal vulnerability scans quarterly
  • 11.3.1.1 Address non-high vulnerabilities per TRA
  • 11.3.1.3 Internal scans after significant changes
  • 11.3.2.1 External scans after significant change
  • 11.4.4 Pen test findings remediated
  • 12.3.2 TRA for customized approach
  • 12.3.3 Cryptographic cipher suites and protocols inventory
  • 12.6.1 Formal security awareness program implemented
  • 2.2.4 Only necessary services enabled
  • 6.2.1 Bespoke and custom software are developed securely, as follows: • Based on industry standards and/or best practices for secure development. • In accordance with PCI DSS (for example, secure authentication and logging). • Incorporating
  • 6.4.1 For public-facing web applications, new threats and vulnerabilities are addressed on an ongoing basis and these applications are protected against known attacks as follows: • Reviewing public-facing web applications via manual or automated application
  • 6.3.1 Security vulnerabilities are identified and managed as follows: • New security vulnerabilities are identified using industry-recognized sources for security vulnerability information, including alerts from international and national computer emergency response teams (CERTs). • Vulnerabilities
  • 6.3.2 An inventory of bespoke and custom software, and third-party software components incorporated into bespoke and custom software is maintained to facilitate vulnerability and patch management

ISO 27701:2019 · 12 controls

  • 5.4 Planning
  • 5.4.1 Actions to address risks and opportunities
  • 5.6.2 Information security risk assessment
  • 5.6.3 Information security risk treatment
  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 6.10.1 Network security management
  • 6.11 Systems acquisition, development and maintenance
  • 6.11.1 Security requirements of information systems
  • 6.9 Operations security
  • 7.4 Privacy by design and privacy by default
  • 8.2 Conditions for collection and processing
  • 8.4 Privacy by design and privacy by default

CIS Controls v8 · 9 controls

  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-7.7 Remediate Detected Vulnerabilities

NIST SP 800-53 Rev 5 · 9 controls

  • NIST800-CA-5 Plan of action and milestones
  • NIST800-CA-7 Continuous monitoring
  • NIST800-PM-28 Risk Framing. Identify and document: Assumptions affecting risk assessments, risk responses, and risk monitoring; Constraints affecting risk assessments, risk responses, and risk monitoring; Priorities and trade-offs considered by the organization for managing risk; and
  • NIST800-PM-30 Supply Chain Risk Management Strategy. Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services; Implement the supply chain risk
  • NIST800-PM-9 Risk Management Strategy. Develops a comprehensive strategy to manage: Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and Privacy risk
  • NIST800-RA-7 Risk response
  • NIST800-SA-8 Security and privacy engineering principles
  • NIST800-SC-38 Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined]
  • SP800-53-RA Risk Assessment Family

ISO 27001:2022 · 7 controls

  • 5.25 Assessment and decision on information security events
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 5.7 Threat intelligence
  • 8.16 Monitoring activities
  • 8.27 Secure system architecture and engineering principles
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
  • NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated

ISO 22301:2019 · 6 controls

  • 6.1 Actions to address risks and opportunities
  • 6.1.1 Determining risks and opportunities
  • 6.1.2 Addressing risks and opportunities
  • 8.1 Operational planning and control
  • 8.2 Business impact analysis and risk assessment
  • 8.2.3 Risk assessment

ISO 27002:2022 · 6 controls

  • 5.24 Information security incident management planning and preparation
  • 5.34 Privacy and protection of PII
  • 5.7 Threat intelligence
  • 8.16 Monitoring activities
  • 8.26 Application security requirements
  • 8.8 Management of technical vulnerabilities

CMMC 2.0 · 5 controls

NIST SP 800-161 Rev 1 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC3.2 COSO principle 7: Identifies risks and analyzes to determine how managed
  • SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner
  • SOC2-CC5.1 COSO principle 10: Selects and develops control activities to mitigate risks
  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place
  • SOC2-CC9.1 Identifies, selects and develops risk mitigation activities

APRA CPS 234 · 4 controls

  • CPS234-15 Information Security Capability
  • CPS234-21 Implementation of Information Security Controls
  • CPS234-28 Escalation of Unremediated Testing Deficiencies
  • CPS234-P17 Active Maintenance of Capability Against Change
  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-17 Enterprise Technology Risk Assessment
  • CFTC-SS-2 Enterprise Risk Management and Governance Category
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies

FedRAMP High · 4 controls

  • CA-5 Plan of Action and Milestones
  • CA-7 Continuous Monitoring
  • RA-3 Risk Assessment
  • SI-2 Flaw Remediation

FedRAMP Moderate · 4 controls

  • CA-5 Plan of Action and Milestones
  • CA-7 Continuous Monitoring
  • RA-3 Risk Assessment
  • SI-2 Flaw Remediation
  • CA-5 Plan of Action and Milestones
  • CA-7 Continuous Monitoring
  • RA-3 Risk Assessment
  • SI-2 Flaw Remediation
  • CA-5 Plan of Action and Milestones
  • CA-7 Continuous Monitoring
  • RA-3 Risk Assessment
  • SI-2 Flaw Remediation
  • CA-5 Plan of Action and Milestones
  • CA-7 Continuous Monitoring
  • RA-3 Risk Assessment
  • SI-2 Flaw Remediation
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-24 Design and Embedding of Internal Controls
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses
  • SEC01-BP07 Identify threats and prioritize mitigations using a threat model
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • SEC06-BP01 Perform vulnerability management

C5 (Germany) · 3 controls

  • C5-OIS-06 Risk Management Policy
  • C5-OIS-07 Application of the Risk Management Policy
  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept

NIST SP 800-171 Rev 3 · 3 controls

ACSC Essential Eight · 2 controls

  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • ANSSI-HYG-41 Conduct a Formal Risk Analysis
  • AUCDR-IS-4 Formal vulnerability management program
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • CPS220-P35 Required Content of Risk Management Policies and Procedures
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities

ISO/IEC 42001:2023 · 1 control

  • 8.3 AI risk treatment

NIST SP 800-172 · 1 control

  • 3.11.4e Security Solution Rationale Document

NIST SP 800-218 · 1 control

UK Cyber Essentials · 1 control

  • CE-FW.1 Boundary Firewalls Deployed

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(1)(ii)(B) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 146 it maps to, and the evidence behind each claim, over MCP and REST.