HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(1)(ii)(D): Information System Activity Review (Required)

Regularly review audit logs, access reports, and security incident tracking reports. NIST recommends defined review frequency, SIEM integration, anomaly detection, and documented review evidence.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 127 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 16 controls

  • 1.2.2 Changes to NSC reviewed and approved
  • 10.2.1.1 Log all user access to CHD
  • 10.2.1.3 Log access to audit logs
  • 10.2.1.5 Log changes to identification and authentication
  • 10.4.1 Daily log review for critical systems
  • 10.4.2 Periodic review of other system component logs
  • 10.4.3 Exceptions and anomalies addressed
  • 10.6.3 Time settings protected
  • 10.7.2 Critical security control failure detection (all entities)
  • 10.7.3 Failure response timeline
  • 11.5.2 Change detection mechanism (FIM)
  • 12.4.1 Executive management responsibility for the PCI DSS compliance program (service providers)
  • 5.3.4 Audit logs for anti-malware enabled
  • 7.2.5.1 App and system account review cadence
  • 9.2.3 Physical access to networking and telecommunications hardware restricted
  • 7.2.4 All user accounts and related access privileges, including third-party/vendor accounts, are reviewed as follows: • At least once every six months. • To ensure user accounts and access remain appropriate based on job function.

NIST SP 800-53 Rev 5 · 10 controls

  • NIST800-AU-10 Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined]
  • NIST800-AU-13 Monitoring for Information Disclosure. Monitor [organization-defined] [organization-defined] for evidence of unauthorized disclosure of organizational information; and If an information disclosure is discovered: Notify [organization-defined] ; and Take the following additional actions: [organization-defined]
  • NIST800-AU-2 Event logging
  • NIST800-AU-6 Audit record review, analysis, and reporting
  • NIST800-CA-7 Continuous monitoring
  • NIST800-IR-5 Incident monitoring
  • NIST800-PM-21 Accounting of Disclosures. Develop and maintain an accurate accounting of disclosures of personally identifiable information, including: Date, nature, and purpose of each disclosure; and Name and address, or other contact information of the individual
  • NIST800-PM-31 Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring
  • NIST800-SI-4 System monitoring
  • SP800-53-RA Risk Assessment Family

CIS Controls v8 · 8 controls

  • CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
  • CIS-13.1 Centralize Security Event Alerting
  • CIS-2.3 Address Unauthorized Software
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.12 Collect Service Provider Logs
  • CIS-8.2 Collect Audit Logs
  • CIS-8.9 Centralize Audit Logs
  • ASBv3-BR-3 Monitor backups
  • ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts
  • ASBv3-LT-1 Enable threat detection capabilities
  • ASBv3-PA-4 Review and reconcile user access regularly
  • DP-2 Monitor anomalies and threats targeting sensitive data
  • LT-5 Centralize security log management and analysis

CMMC 2.0 · 6 controls

FedRAMP High · 6 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • SA-1 Policy and Procedures
  • SI-4 System Monitoring

FedRAMP Moderate · 6 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • SA-1 Policy and Procedures
  • SI-4 System Monitoring
  • AC-2(12) Account Monitoring for Atypical Usage
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • SA-1 Policy and Procedures
  • SI-4 System Monitoring
  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-03 Information is correlated from multiple sources
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

NIST SP 800-171 Rev 3 · 5 controls

  • 03.03.05 Audit Record Review, Analysis, and Reporting
  • 03.03.06 Audit Record Reduction and Report Generation
  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance
  • 03.12.03 Continuous Monitoring
  • 03.14.06 System Monitoring
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • SA-1 Policy and Procedures
  • SI-4 System Monitoring
  • SEC02-BP05 Audit and rotate credentials periodically
  • SEC03-BP07 Analyze public and cross-account access
  • SEC04-BP02 Capture logs, findings, and metrics in standardized locations
  • SEC04-BP03 Correlate and enrich security alerts

C5 (Germany) · 4 controls

  • C5-COM-04 Information on information security performance and management assessment of the ISMS
  • C5-IDM-05 Regular review of access rights
  • C5-OPS-10 Logging and Monitoring - Concept
  • C5-OPS-13 Logging and Monitoring - Identification of Events

ISO 27001:2022 · 4 controls

  • 5.25 Assessment and decision on information security events
  • 5.35 Independent review of information security
  • 8.15 Logging
  • 8.16 Monitoring activities

ISO 27002:2022 · 4 controls

  • 5.25 Assessment and decision on information security events
  • 5.35 Independent review of information security
  • 8.15 Logging
  • 8.16 Monitoring activities

SOC 2 · 4 controls

  • SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
  • SOC2-CC5.2 COSO principle 11: Selects and develops general controls over technology
  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place
  • SOC2-CC7.2 Monitors system components for anomalies indicating malicious acts
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • AUCDR-IS-STEP5 Step 5 - Manage and report security incidents
  • AU-6 Audit Record Review, Analysis, and Reporting
  • SA-1 Policy and Procedures
  • SI-4 System Monitoring

ACSC Essential Eight · 2 controls

  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

APRA CPS 234 · 2 controls

  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-31 Hunt to discover incidents (Very Good)

ISO 22301:2019 · 2 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2.2 Audit programme(s)

ISO 27701:2019 · 2 controls

  • 6.9.4 Logging and monitoring
  • 6.9.7 Information systems audit considerations

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.11.3e Advanced Automation and Analytics Capabilities
  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components
  • CBPR-PR-32 Detection, prevention and response measures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(1)(ii)(D) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 127 it maps to, and the evidence behind each claim, over MCP and REST.