NIST SP 800-66 Rev 2
Administrative

NIST SP 800-66 Rev 2 164.308(a)(1)(ii)(A): Risk Analysis (Required)

Conduct accurate and thorough assessment of potential risks and vulnerabilities to ePHI. NIST recommends the nine-step risk analysis methodology and integration with NIST SP 800-30 and the NIST RMF.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 167 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 29 controls

  • 1.2.3 1.2.3 Accurate network diagram of CDE connections
  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks
  • 10.4.2.1 10.4.2.1 Periodic log review frequency set by targeted risk analysis
  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 11.2.1 11.2.1 Detect authorized and rogue wireless access points
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 11.4.1 11.4.1 Penetration testing methodology defined and implemented
  • 11.4.3 11.4.3 External penetration testing annually and after change
  • 11.4.5 11.4.5 Annual segmentation penetration testing
  • 11.4.6 11.4.6 Service provider segmentation testing every six months
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 12.5.3 12.5.3 Scope review after significant organisational change
  • 12.6.1 12.6.1 Formal security awareness program
  • 3.3.3 3.3.3 Issuer SAD storage limited, justified and encrypted
  • 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication
  • 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency
  • 5.3.2.1 5.3.2.1 Targeted risk analysis sets malware scan frequency
  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 9.4.5.1 9.4.5.1 Annual inventories of electronic media
  • 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.2 6.3.2 Inventory of bespoke software and components
  • 8.6.3 8.6.3 System account passwords protected against misuse

NIST SP 800-53 Rev 5 · 20 controls

CIS Controls v8 · 17 controls

  • CIS-1.3 Utilize an Active Discovery Tool
  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-13.8 Deploy a Network Intrusion Prevention Solution
  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.14 Conduct Threat Modeling
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.6 Allowlist Authorized Libraries
  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-4.4 Implement and Manage a Firewall on Servers
  • CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients

ISO 27701:2019 · 14 controls

  • 5.2.1 Understanding the organization and its context
  • 5.4 Planning
  • 5.4.1 Actions to address risks and opportunities
  • 5.6.2 Information security risk assessment
  • 6.10.1 Network security management
  • 6.11 Systems acquisition, development and maintenance
  • 6.11.1 Security requirements of information systems
  • 6.9 Operations security
  • 6.9.6 Technical vulnerability management
  • 7.2.5 Privacy impact assessment
  • 7.4 Privacy by design and privacy by default
  • 7.4.4 PII minimization objectives
  • 8.2 Conditions for collection and processing
  • 8.4 Privacy by design and privacy by default
  • NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-ID.RA-03 Internal and external threats to the organization are identified and recorded
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

ISO 27001:2022 · 9 controls

  • 5.23 Information security for use of cloud services
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 5.7 Threat intelligence
  • 5.9 Inventory of information and other associated assets
  • 8.19 Installation of software on operational systems
  • 8.27 Secure system architecture and engineering principles
  • 8.29 Security testing in development and acceptance
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

ISO 22301:2019 · 8 controls

  • 4.2.1 General
  • 6.1 Actions to address risks and opportunities
  • 6.1.1 Determining risks and opportunities
  • 6.1.2 Addressing risks and opportunities
  • 8.1 Operational planning and control
  • 8.2 Business impact analysis and risk assessment
  • 8.2.1 General
  • 8.2.3 Risk assessment

ISO 27002:2022 · 8 controls

  • 5.34 Privacy and protection of PII
  • 5.35 Independent review of information security
  • 5.7 Threat intelligence
  • 5.9 Inventory of information and other associated assets
  • 8.19 Installation of software on operational systems
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.8 Management of technical vulnerabilities

SOC 2 · 8 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications

CMMC 2.0 · 5 controls

  • ASBv3-AM-1 Track asset inventory and their risks
  • ASBv3-DP-1 Discover, classify, and label sensitive data
  • ASBv3-DS-1 Conduct threat modeling
  • PV-5 Perform vulnerability assessments
  • AUCDR-IS-4 Formal vulnerability management program
  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-17 Enterprise Technology Risk Assessment
  • CFTC-SS-2 Enterprise Risk Management and Governance Category

NIST SP 800-171 Rev 3 · 3 controls

  • CPS220-07 Material Risk Categories the Framework Must Address
  • CPS220-P22 Framework Structure for Managing Each Material Risk
  • SEC01-BP07 Identify threats and prioritize mitigations using a threat model
  • SEC06-BP01 Perform vulnerability management

C5 (Germany) · 2 controls

FedRAMP High · 2 controls

NIST SP 800-161 Rev 1 · 2 controls

  • CPS230-11 Identification, Assessment and Management of Operational Risk

APRA CPS 234 · 1 control

  • CPS234-20 Information Asset Classification

FedRAMP Moderate · 1 control

  • RA-3 Risk Assessment

ISO 31000:2018 · 1 control

ISO/IEC 23894:2023 · 1 control

  • 6.4.3 Risk analysis

NIST SP 800-172 · 1 control

  • 3.11.1e Threat-Aware Risk Assessment

UK Cyber Essentials · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

Query this from an agent

The graph holds this control, the 167 it maps to, and the evidence behind each claim, over MCP and REST.