HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(3)(ii)(A): Authorization and Supervision (Addressable)

Implement procedures for authorization and supervision of workforce members who work with ePHI. NIST recommends formal approval workflows and supervisory checks for sensitive functions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 59 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 5 controls

  • 5.18 Access rights
  • 5.2 Information security roles and responsibilities
  • 5.4 Management responsibilities
  • 6.1 Screening
  • 8.2 Privileged access rights

ISO 27002:2022 · 5 controls

  • 5.18 Access rights
  • 5.2 Information security roles and responsibilities
  • 5.4 Management responsibilities
  • 6.1 Screening
  • 6.2 Terms and conditions of employment

NIST SP 800-53 Rev 5 · 5 controls

PCI DSS 4.0 · 5 controls

  • 7.2.3 7.2.3 Privileges approved by authorized personnel
  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 9.3.2 9.3.2 Visitor access procedures for the CDE
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • ASBv3-IM-2 Protect identity and authentication systems
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle
  • PA-1 Separate and limit highly privileged/administrative users
  • PA-2 Avoid standing access for user accounts and permissions

C5 (Germany) · 3 controls

  • C5-HR-02 Employment terms and conditions
  • C5-IDM-02 Granting and change of user accounts and access rights
  • C5-IDM-06 Privileged access rights

SOC 2 · 3 controls

  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • MYHR-SEC-2 Access controls and user account management
  • MYHR-SEC-3 Audit logging and access monitoring

CMMC 2.0 · 2 controls

FedRAMP High · 2 controls

  • AC-2 Account Management
  • AC-6 Least Privilege

FedRAMP Moderate · 2 controls

  • AC-2 Account Management
  • AC-6 Least Privilege

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

UK Cyber Essentials · 2 controls

  • CE-AC.1 User Account Approval Process
  • CE-AC.5 Separate Admin Accounts for Administrative Activities
  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)

APPI · 1 control

  • ASD37-18 Restrict administrative privileges (Essential)

CIS Controls v8 · 1 control

  • CIS-6.1 Establish an Access Granting Process

ISO 27701:2019 · 1 control

  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-172 · 1 control

  • 3.1.1e Dual Authorization for Sensitive System Operations

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(3)(ii)(A) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 59 it maps to, and the evidence behind each claim, over MCP and REST.