NIST SP 800-66 Rev 2
Technical

NIST SP 800-66 Rev 2 164.312(c)(2): Mechanism to Authenticate ePHI (Addressable)

Implement electronic mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner. NIST recommends hash-based or signed integrity verification.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 20 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 6 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-PI1.3 PI1.3 Controls over system processing
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration
  • NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

FedRAMP High · 1 control

FedRAMP Moderate · 1 control

ISO 27001:2022 · 1 control

  • 8.24 Use of cryptography

ISO 27002:2022 · 1 control

  • 8.24 Use of cryptography

ISO 27701:2019 · 1 control

  • 6.7.1 Cryptographic controls
  • 161R1-SI-7 Software, Firmware, and Information Integrity

NIST SP 800-172 · 1 control

  • 3.14.1e Verify Integrity of Security Critical Software and Firmware
  • NIST800-SI-7 SI-7 Software, Firmware, and Information Integrity

PCI DSS 4.0 · 1 control

  • 10.3.4 10.3.4 File integrity monitoring on audit logs

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technical

Query this from an agent

The graph holds this control, the 20 it maps to, and the evidence behind each claim, over MCP and REST.