NIST SP 800-66 Rev 2
Administrative

NIST SP 800-66 Rev 2 164.308(a)(3)(i): Workforce Security (Standard)

Implement policies ensuring workforce members have appropriate access to ePHI and that those who should not have access are prevented from obtaining it.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 63 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 9 controls

  • 2.1.2 2.1.2 Requirement 2 roles and responsibilities assigned
  • 4.1.2 4.1.2 Requirement 4 roles and responsibilities assigned
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 8.2.5 8.2.5 Terminated users' access revoked immediately
  • 9.1.2 9.1.2 Requirement 9 roles and responsibilities assigned
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • 8.1.2 8.1.2 Requirement 8 roles and responsibilities assigned

CMMC 2.0 · 5 controls

CIS Controls v8 · 4 controls

  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.8 Define and Maintain Role-Based Access Control

NIST SP 800-171 Rev 3 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

FedRAMP High · 3 controls

  • AC-2 Account Management
  • PS-1 Policy and Procedures
  • PS-3 Personnel Screening

FedRAMP Moderate · 3 controls

  • AC-2 Account Management
  • PS-1 Policy and Procedures
  • PS-3 Personnel Screening

SOC 2 · 3 controls

  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-P5.1 P5.1 Data subject access

UK Cyber Essentials · 3 controls

  • CE-AC.1 User Account Approval Process
  • CE-AC.3 Remove or Disable Accounts When No Longer Required
  • CE-AC.4 Privileged Account Approval and Tracking
  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle
  • PA-3 Manage lifecycle of identities and entitlements

C5 (Germany) · 2 controls

  • C5-HR-01 Verification of qualification and trustworthiness
  • C5-IDM-01 Policy for user accounts and access rights

ISO 27001:2022 · 2 controls

ISO 27002:2022 · 2 controls

  • 5.18 Access rights
  • 7.6 Working in secure areas

ISO 27701:2019 · 2 controls

  • 6.4.2 During employment
  • 6.6.2 User access management
  • NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-161 Rev 1 · 2 controls

  • CBPR-PR-27 Physical, technical and administrative safeguards

APPI · 1 control

  • ASD37-18 Restrict administrative privileges (Essential)
  • AUCDR-IS-6 Information security training and awareness program
  • MYHR-SEC-2 Access controls and user account management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

Query this from an agent

The graph holds this control, the 63 it maps to, and the evidence behind each claim, over MCP and REST.