HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(1)(ii)(D): Information System Activity Review (Required)

Regularly review audit logs, access reports, and security incident tracking reports. NIST recommends defined review frequency, SIEM integration, anomaly detection, and documented review evidence.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 113 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 16 controls

  • 1.2.2 1.2.2 Network connection and NSC changes under change control
  • 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data
  • 10.2.1.3 10.2.1.3 Access to the audit logs is itself logged
  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 10.4.2 10.4.2 Periodic review of all other system component logs
  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 11.5.2 11.5.2 Change detection on critical files
  • 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program
  • 5.3.4 5.3.4 Anti-malware audit logs enabled and retained
  • 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months

NIST SP 800-53 Rev 5 · 10 controls

CIS Controls v8 · 8 controls

  • CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
  • CIS-13.1 Centralize Security Event Alerting
  • CIS-2.3 Address Unauthorized Software
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.12 Collect Service Provider Logs
  • CIS-8.2 Collect Audit Logs
  • CIS-8.9 Centralize Audit Logs
  • ASBv3-BR-3 Monitor backups
  • ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts
  • ASBv3-LT-1 Enable threat detection capabilities
  • ASBv3-PA-4 Review and reconcile user access regularly
  • DP-2 Monitor anomalies and threats targeting sensitive data
  • LT-5 Centralize security log management and analysis

CMMC 2.0 · 6 controls

FedRAMP High · 6 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • SA-1 Policy and Procedures
  • SI-4 System Monitoring

FedRAMP Moderate · 6 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • SA-1 Policy and Procedures
  • SI-4 System Monitoring
  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-03 Information is correlated from multiple sources
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

NIST SP 800-171 Rev 3 · 5 controls

  • 03.03.05 Audit Record Review, Analysis, and Reporting
  • 03.03.06 Audit Record Reduction and Report Generation
  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance
  • 03.12.03 Continuous Monitoring
  • 03.14.06 System Monitoring
  • SEC02-BP05 Audit and rotate credentials periodically
  • SEC03-BP07 Analyze public and cross-account access
  • SEC04-BP02 Capture logs, findings, and metrics in standardized locations
  • SEC04-BP03 Correlate and enrich security alerts

C5 (Germany) · 4 controls

  • C5-COM-04 Information on information security performance and management assessment of the ISMS
  • C5-IDM-05 Regular review of access rights
  • C5-OPS-10 Logging and Monitoring - Concept
  • C5-OPS-13 Logging and Monitoring - Identification of Events

ISO 27001:2022 · 4 controls

  • 5.25 Assessment and decision on information security events
  • 5.35 Independent review of information security
  • 8.15 Logging
  • 8.16 Monitoring activities

ISO 27002:2022 · 4 controls

  • 5.25 Assessment and decision on information security events
  • 5.35 Independent review of information security
  • 8.15 Logging
  • 8.16 Monitoring activities

SOC 2 · 4 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • AUCDR-IS-STEP5 Step 5 - Manage and report security incidents

ACSC Essential Eight · 2 controls

  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • E8-APP-ML3 Application Control (ML3)
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

APRA CPS 234 · 2 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-30 Detection and Response Mechanisms
  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-31 Hunt to discover incidents (Very Good)

ISO 22301:2019 · 2 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2.2 Audit programme(s)

ISO 27701:2019 · 2 controls

  • 6.9.4 Logging and monitoring
  • 6.9.7 Information systems audit considerations

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.11.3e Advanced Automation and Analytics Capabilities
  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components
  • CBPR-PR-32 Detection, prevention and response measures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(1)(ii)(D) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 113 it maps to, and the evidence behind each claim, over MCP and REST.