NIST SP 800-66 Rev 2
Technical

NIST SP 800-66 Rev 2 164.312(a)(2)(ii): Emergency Access Procedure (Required)

Establish procedures for obtaining necessary ePHI during an emergency. NIST recommends break-glass accounts, time-bounded activation, and full logging.

What else in your programme already covers this

This control maps to 28 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 6 controls

  • SOC2-A1.3 Recovery plan procedures support system recovery from failures
  • SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
  • SOC2-CC6.3 Role-based access and least privilege are enforced
  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place
  • SOC2-CC7.4 Responds to identified security incidents through defined procedures
  • SOC2-CC9.1 Identifies, selects and develops risk mitigation activities

NIST SP 800-53 Rev 5 · 4 controls

  • NIST800-AC-6 Least privilege
  • NIST800-AU-12 Audit record generation
  • NIST800-CP-13 Alternative Security Mechanisms. Employ [organization-defined] for satisfying [organization-defined] when the primary means of implementing the security function is unavailable or compromised
  • NIST800-CP-2 Contingency plan

ISO 27001:2022 · 3 controls

  • 5.29 Information security during disruption
  • 8.15 Logging
  • 8.2 Privileged access rights

ISO 27002:2022 · 3 controls

  • 5.29 Information security during disruption
  • 8.15 Logging
  • 8.2 Privileged access rights

ISO 27701:2019 · 2 controls

  • 6.14.1 Information security continuity
  • 6.9.4 Logging and monitoring

FedRAMP High · 1 control

  • AC-2(2) Automated Temporary and Emergency Account Management

FedRAMP Moderate · 1 control

  • AC-2(2) Automated Temporary and Emergency Account Management
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • AC-2(2) Automated Temporary and Emergency Account Management
  • AC-2(2) Automated Temporary and Emergency Account Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technical

Query this from an agent

The graph holds this control, the 28 it maps to, and the evidence behind each claim, over MCP and REST.