NIST SP 800-66 Rev 2
Technical

NIST SP 800-66 Rev 2 164.312(a)(1): Access Control (Standard)

Implement technical policies and procedures to allow only authorized persons or software programs access to ePHI. NIST recommends identity, authentication, authorization, and session management aligned to SP 800-53 AC family.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 96 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 8 controls

  • 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks
  • 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 7.2.1 7.2.1 Access control model defined
  • 7.3.2 7.3.2 Access control system enforces role-based permissions
  • 7.3.3 7.3.3 Access control default deny all
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.3.1 7.3.1 Need-to-know access control system covers all components

CIS Controls v8 · 7 controls

  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
  • CIS-2.6 Allowlist Authorized Libraries
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control

NIST SP 800-53 Rev 5 · 6 controls

SOC 2 · 6 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-P5.1 P5.1 Data subject access

ACSC Essential Eight · 5 controls

  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)
  • E8-ADMIN-ML3 Restrict Administrative Privileges (ML3)
  • E8-APP-ML1 Application Control (ML1)
  • E8-BACKUP-ML2 Regular Backups (ML2)
  • E8-BACKUP-ML3 Regular Backups (ML3)
  • ASBv3-AM-4 Limit access to asset management
  • ASBv3-IM-9 Secure user access to existing applications
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle
  • IM-1 Use centralized identity and authentication system
  • IM-7 Restrict resource access based on conditions

CMMC 2.0 · 5 controls

ISO 27002:2022 · 5 controls

  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 8.19 Installation of software on operational systems
  • 8.3 Information access restriction
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented

NIST SP 800-171 Rev 3 · 4 controls

FedRAMP High · 3 controls

  • AC-2 Account Management
  • AC-3 Access Enforcement
  • AU-9 Protection of Audit Information

FedRAMP Moderate · 3 controls

  • AC-2 Account Management
  • AC-3 Access Enforcement
  • AU-9 Protection of Audit Information

ISO 27001:2022 · 3 controls

  • 5.15 Access control
  • 8.19 Installation of software on operational systems
  • 8.3 Information access restriction

ISO 27701:2019 · 3 controls

  • 6.11.1 Security requirements of information systems
  • 6.6 Access control
  • 6.6.2 User access management

UK Cyber Essentials · 3 controls

  • CE-AC.2 Authenticate Users Before Granting Access
  • CE-AC.4 Privileged Account Approval and Tracking
  • CE-AC.5 Separate Admin Accounts for Administrative Activities
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need
  • CBPR-06 Security Safeguards
  • CBPR-PR-27 Physical, technical and administrative safeguards
  • ASD37-01 Application control (Essential)
  • ASD37-18 Restrict administrative privileges (Essential)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data
  • MYHR-SEC-2 Access controls and user account management
  • MYHR-SEC-7 Consumer access controls and consent

C5 (Germany) · 2 controls

APPI · 1 control

  • APP-11 APP 11 - Security of personal information

NIST SP 800-172 · 1 control

  • 3.13.2e Introduce Unpredictability into System Operations

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technical

Query this from an agent

The graph holds this control, the 96 it maps to, and the evidence behind each claim, over MCP and REST.