NIST SP 800-66
Workforce Security + Access + Training

NIST SP 800-66 NISTSP66-2: Workforce Security, Information Access Management, and Awareness Training

Implement HIPAA Security Rule Administrative Safeguards covering workforce + access + training. Workforce Security per 45 CFR 164.308(a)(3): Authorization and/or Supervision of workforce members + Workforce Clearance Procedures + Termination Procedures ensuring access revocation when employment ends or roles change. Information Access Management per 45 CFR 164.308(a)(4): Isolating Health Care Clearinghouse Functions + Access Authorization (procedures for granting access to ePHI through workstation + transaction + program + process) + Access Establishment and Modification (procedures to establish + document + review + modify access rights). Security Awareness and Training per 45 CFR 164.308(a)(5): Security Reminders + Protection from Malicious Software + Log-In Monitoring + Password Management. Apply minimum necessary principle per 45 CFR 164.502(b) when establishing access. Maintain workforce roster + access reviews + recertification cycles + training completion records + phishing simulation evidence.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 109 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27799:2025 · 5 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-07 Workforce security and clearance procedures
  • ISO27799-08 Information access management
  • ISO27799-09 Security awareness and training program
  • ISO27799-17 Facility access controls

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • CAT-D1-4 Training and culture
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures
  • ISO28001-PI-01 Personnel Security Screening
  • ISO28001-PI-02 Security Awareness and Training
  • ISO28001-PS-01 Facility Security

ISO/IEC 27010:2015 · 3 controls

  • 27010-7.1 Information Classification for Sharing
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.3 Segregation of duties
  • 27011-6.3 Awareness and Training
  • 27011-8.1 User Endpoint Devices

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/SAE 21434 · 3 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification

NIST SP 1800-32 · 3 controls

  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CJIS-2 Security Awareness Training
  • CJIS-3 Personnel Security
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

OWASP ASVS · 2 controls

  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • ASD37-37 Personnel management (Very Good)
  • ACQS-7-3 Worker Screening

Bahrain PDPL · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 62351-8 Role-based access control (RBAC)
  • ISO20000-15 Access management for services

ITIL 4 · 1 control

  • ITIL4-15 Access management for services
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA

OWASP MASVS · 1 control

OWASP Top 10:2025 · 1 control

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 109 it maps to, and the evidence behind each claim, over MCP and REST.