NIST SP 800-66 Rev 2
Technical

NIST SP 800-66 Rev 2 164.312(c)(1): Integrity (Standard)

Implement policies and procedures to protect ePHI from improper alteration or destruction. NIST recommends integrity controls including checksums, signed records, and tamper detection.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 62 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 8 controls

  • CIS-11.2 Perform Automated Backups
  • CIS-13.3 Deploy a Network Intrusion Detection Solution
  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-2.6 Allowlist Authorized Libraries
  • CIS-3.11 Encrypt Sensitive Data at Rest
  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-8.5 Collect Detailed Audit Logs

SOC 2 · 7 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications
  • SOC2-PI1.3 PI1.3 Controls over system processing
  • SOC2-PI1.5 PI1.5 Controls over stored inputs, work in process and outputs

NIST SP 800-53 Rev 5 · 6 controls

ISO 27002:2022 · 5 controls

  • 5.33 Protection of records
  • 5.34 Privacy and protection of PII
  • 8.15 Logging
  • 8.24 Use of cryptography
  • 8.32 Change management
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed

PCI DSS 4.0 · 4 controls

  • 10.3.2 10.3.2 Audit log files protected from modification
  • 10.3.4 10.3.4 File integrity monitoring on audit logs
  • 11.5.2 11.5.2 Change detection on critical files
  • 3.5.1 3.5.1 Stored PAN rendered unreadable
  • AUCDR-IS-2 Secure the network and systems within the data environment
  • AUCDR-PS-11 Privacy Safeguard 11 - Quality of CDR data
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • BR-2 Protect backup and recovery data

C5 (Germany) · 2 controls

FedRAMP High · 2 controls

  • SI-1 Policy and Procedures
  • SI-7 Software, Firmware, and Information Integrity

FedRAMP Moderate · 2 controls

  • SI-1 Policy and Procedures
  • SI-7 Software, Firmware, and Information Integrity

NIST SP 800-171 Rev 3 · 2 controls

  • E8-APP-ML1 Application Control (ML1)
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources

APPI · 1 control

  • APPI-A22 Accuracy and Deletion of Personal Data
  • APP-10 APP 10 - Quality of personal information

CMMC 2.0 · 1 control

ISO 27001:2022 · 1 control

  • 5.33 Protection of records

ISO 27701:2019 · 1 control

  • 6.11 Systems acquisition, development and maintenance
  • 161R1-SI-7 Software, Firmware, and Information Integrity

NIST SP 800-172 · 1 control

  • 3.14.1e Verify Integrity of Security Critical Software and Firmware

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technical

Query this from an agent

The graph holds this control, the 62 it maps to, and the evidence behind each claim, over MCP and REST.