Frameworks / NIST SP 800-66 Rev 2 / 164.312(c)(1) NIST SP 800-66 Rev 2
Technical
NIST SP 800-66 Rev 2 164.312(c)(1): Integrity (Standard) Implement policies and procedures to protect ePHI from improper alteration or destruction. NIST recommends integrity controls including checksums, signed records, and tamper detection.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 62 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-11.2 Perform Automated Backups CIS-13.3 Deploy a Network Intrusion Detection Solution CIS-16.1 Establish and Maintain a Secure Application Development Process CIS-2.6 Allowlist Authorized Libraries CIS-3.11 Encrypt Sensitive Data at Rest CIS-3.13 Deploy a Data Loss Prevention Solution CIS-3.3 Configure Data Access Control Lists CIS-8.5 Collect Detailed Audit Logs SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications SOC2-PI1.3 PI1.3 Controls over system processing SOC2-PI1.5 PI1.5 Controls over stored inputs, work in process and outputs 5.33 Protection of records 5.34 Privacy and protection of PII 8.15 Logging 8.24 Use of cryptography 8.32 Change management NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed 10.3.2 10.3.2 Audit log files protected from modification 10.3.4 10.3.4 File integrity monitoring on audit logs 11.5.2 11.5.2 Change detection on critical files 3.5.1 3.5.1 Stored PAN rendered unreadable AUCDR-IS-2 Secure the network and systems within the data environment AUCDR-PS-11 Privacy Safeguard 11 - Quality of CDR data ASBv3-PV-4 Audit and enforce secure configurations for compute resources BR-2 Protect backup and recovery data SI-1 Policy and Procedures SI-7 Software, Firmware, and Information Integrity SI-1 Policy and Procedures SI-7 Software, Firmware, and Information Integrity E8-APP-ML1 Application Control (ML1) ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources APPI-A22 Accuracy and Deletion of Personal Data APP-10 APP 10 - Quality of personal information 5.33 Protection of records 6.11 Systems acquisition, development and maintenance 161R1-SI-7 Software, Firmware, and Information Integrity 3.14.1e Verify Integrity of Security Critical Software and Firmware Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Technical Query this from an agent The graph holds this control, the 62 it maps to, and the evidence behind each claim, over MCP and REST.