NIST SP 800-66
Physical Safeguards

NIST SP 800-66 NISTSP66-5: Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls

Implement HIPAA Security Rule Physical Safeguards per 45 CFR 164.310. Facility Access Controls per 45 CFR 164.310(a): Contingency Operations + Facility Security Plan + Access Control and Validation Procedures + Maintenance Records (all Addressable). Workstation Use per 45 CFR 164.310(b): specify proper functions to be performed + manner of performance + physical attributes of the surroundings of a specific workstation or class of workstation that can access ePHI. Workstation Security per 45 CFR 164.310(c): implement physical safeguards for all workstations that access ePHI to restrict access to authorized users. Device and Media Controls per 45 CFR 164.310(d): Disposal (Required) + Media Re-use (Required) + Accountability (Addressable) + Data Backup and Storage (Addressable) covering hardware and electronic media that contain ePHI + procedures for receipt and removal of hardware and electronic media into and out of facility. Apply NIST SP 800-88 Guidelines for Media Sanitization for disposal and re-use.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 81 controls across 44 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO 27799:2025 · 3 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-08 Information access management
  • ISO27799-17 Facility access controls

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/SAE 21434 · 3 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification

NIST SP 1800-32 · 3 controls

  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls

ISO/IEC 27010:2015 · 2 controls

  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices

OWASP ASVS · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Bahrain PDPL · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 62351-8 Role-based access control (RBAC)
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ITIL 4 · 1 control

  • ITIL4-15 Access management for services
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP Top 10:2025 · 1 control

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 81 it maps to, and the evidence behind each claim, over MCP and REST.