HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(8): Evaluation (Standard)

Perform periodic technical and nontechnical evaluation. NIST recommends combining policy review, control testing, vulnerability assessments, and audits to evaluate ongoing compliance.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 155 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 27 controls

  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 10.4.2.1 10.4.2.1 Periodic log review frequency set by targeted risk analysis
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 11.4.1 11.4.1 Penetration testing methodology defined and implemented
  • 11.4.2 11.4.2 Internal penetration testing annually and after change
  • 11.4.3 11.4.3 External penetration testing annually and after change
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 11.4.5 11.4.5 Annual segmentation penetration testing
  • 11.4.6 11.4.6 Service provider segmentation testing every six months
  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 12.5.2 12.5.2 Annual and change-driven scope confirmation
  • 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers
  • 12.5.3 12.5.3 Scope review after significant organisational change
  • 12.6.1 12.6.1 Formal security awareness program
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency
  • 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.5.2 6.5.2 Confirm PCI DSS controls after significant change
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months

CIS Controls v8 · 10 controls

  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-17.8 Conduct Post-Incident Reviews
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.4 Validate Security Measures
  • CIS-18.5 Perform Periodic Internal Penetration Tests
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets

NIST SP 800-53 Rev 5 · 9 controls

  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established

ISO 27001:2022 · 6 controls

  • 5.27 Learning from information security incidents
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.29 Security testing in development and acceptance
  • 8.30 Outsourced development
  • 8.8 Management of technical vulnerabilities

ISO 27701:2019 · 6 controls

  • 5.4 Planning
  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 5.7.2 Internal audit
  • 6.15 Compliance
  • 6.15.2 Information security reviews
  • 8.4 Privacy by design and privacy by default

APRA CPS 234 · 5 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-P17 Active Maintenance of Capability Against Change
  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P31 Annual Review of Testing Program Sufficiency

C5 (Germany) · 5 controls

  • C5-COM-02 Policy for planning and conducting audits
  • C5-COM-03 Internal audits of the information security management system
  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

FedRAMP High · 5 controls

  • CA-1 Policy and Procedures
  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • RA-5 Vulnerability Monitoring and Scanning

FedRAMP Moderate · 5 controls

  • CA-1 Policy and Procedures
  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-7 Continuous Monitoring
  • RA-5 Vulnerability Monitoring and Scanning
  • CPS220-11 Annual Audit Review of the Framework
  • CPS220-18 Triennial Comprehensive Review of the Framework
  • CPS220-P47 Minimum Assessment Required by the Framework Review
  • CPS220-P48 Assessment Following Material Change Outside the Review Cycle
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • CPS230-66 Review of Operational Risk Management
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness
  • SEC01-BP03 Identify and validate control objectives
  • SEC01-BP08 Evaluate and implement new security services and features regularly
  • SEC06-BP01 Perform vulnerability management
  • SEC11-BP03 Perform regular penetration testing
  • ASBv3-GS-5 Define and implement security posture management strategy
  • ASBv3-PV-7 Conduct regular red team operations
  • PV-2 Audit and enforce secure configurations
  • PV-5 Perform vulnerability assessments

ISO 22301:2019 · 4 controls

  • 8.6 Evaluation of business continuity documentation and capabilities
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2 Internal audit
  • 9.3 Management review

ISO 27002:2022 · 4 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities
  • 8.8 Management of technical vulnerabilities

NIST SP 800-161 Rev 1 · 4 controls

NIST SP 800-171 Rev 3 · 4 controls

SOC 2 · 4 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • AUCDR-IS-4 Formal vulnerability management program
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program

CMMC 2.0 · 3 controls

NIST SP 800-172 · 3 controls

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 3.12.1e Penetration Testing by Independent Agents
  • 3.14.7e Verify Correctness of Security Functions
  • 53A-3.1 Prepare for Control Assessments
  • 53A-3.3 Conduct Control Assessments
  • 53A-E Assessment Reports
  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • CBPR-PR-33 Testing the effectiveness of safeguards
  • AEO-13 Measurement, Analyses and Improvement

ISO/IEC 42001:2023 · 1 control

  • 9.2 Internal audit

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(8) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 155 it maps to, and the evidence behind each claim, over MCP and REST.