HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(5)(ii)(C): Log-in Monitoring (Addressable)

Implement procedures for monitoring log-in attempts and reporting discrepancies. NIST recommends automated alerts on failed authentication thresholds and anomalous login patterns.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 50 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 6 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.2 Collect Audit Logs
  • CIS-8.5 Collect Detailed Audit Logs

NIST SP 800-53 Rev 5 · 6 controls

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

NIST SP 800-171 Rev 3 · 3 controls

PCI DSS 4.0 · 3 controls

  • 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes

C5 (Germany) · 2 controls

  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • C5-OPS-13 Logging and Monitoring - Identification of Events

CMMC 2.0 · 2 controls

FedRAMP High · 2 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-7 Unsuccessful Logon Attempts

FedRAMP Moderate · 2 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-7 Unsuccessful Logon Attempts

ISO 27001:2022 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components
  • ASBv3-LT-2 Enable threat detection for identity and access management

ISO 27002:2022 · 1 control

  • 8.16 Monitoring activities

ISO 27701:2019 · 1 control

  • 6.9.4 Logging and monitoring

NIST SP 800-172 · 1 control

  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities

UK Cyber Essentials · 1 control

  • CE-SC.5 Password-Based Authentication Quality

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(5)(ii)(C) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 50 it maps to, and the evidence behind each claim, over MCP and REST.