Frameworks / NIST SP 800-66 / NISTSP66-6 NIST SP 800-66
Technical Safeguards
NIST SP 800-66 NISTSP66-6: Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication Implement HIPAA Security Rule Technical Safeguards per 45 CFR 164.312 covering technical access + audit + integrity + authentication. Access Control per 45 CFR 164.312(a)(1): Unique User Identification (Required) + Emergency Access Procedure (Required) + Automatic Logoff (Addressable) + Encryption and Decryption (Addressable) at rest. Audit Controls per 45 CFR 164.312(b): implement hardware + software + procedural mechanisms that record and examine activity in information systems that contain or use ePHI. Integrity per 45 CFR 164.312(c)(1): implement policies and procedures to protect ePHI from improper alteration or destruction including Mechanism to Authenticate ePHI (Addressable). Person or Entity Authentication per 45 CFR 164.312(d): implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. Transmission Security per 45 CFR 164.312(e)(1): Integrity Controls (Addressable) + Encryption (Addressable) of ePHI in transit. Encryption at rest and in transit although technically Addressable have effectively become Required per OCR guidance and Safe Harbor for breach notification.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 322 controls across 88 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27799-01 ePHI access controls and authorization ISO27799-02 ePHI encryption at rest and in transit ISO27799-03 Minimum necessary standard enforcement ISO27799-04 Patient data de-identification procedures ISO27799-05 Audit trail for ePHI access ISO27799-08 Information access management ISO27799-12 Unique user identification and authentication ISO27799-16 Transmission security and encryption ISO27799-17 Facility access controls ISO27043-11 Access control policy and enforcement ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO27043-24 Logging and monitoring ISO21434-12 User access management and provisioning ISO21434-13 Authentication and password management ISO21434-14 Privileged access management ISO21434-15 Access review and recertification ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management ISO21434-24 Logging and monitoring BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-08 Cryptographic protection of data BSI-28 Audit event logging and storage BSI-29 Audit record review and analysis BSI-31 Audit log protection and retention AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms AWWA-2.4 Physical Access Controls AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection AWWA-4.4 Audit Logging and Monitoring 27011-5.2 Information Security Roles in Telecoms 27011-5.3 Segregation of duties 27011-6.3 Awareness and Training 27011-8.1 User Endpoint Devices 27011-8.3 Cryptography and key management 27011-8.4 Logging and monitoring 27011-8.6 Data protection and backup CH-FADP-13 Right to object and request blocking CH-FADP-15 Cooperation with the FDPIC CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) OWASPTOP10-1 A01:2025 Broken Access Control OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) OWASPTOP10-6 A06:2025 Vulnerable and Outdated Components OWASPTOP10-7 A07:2025 Identification and Authentication Failures OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures ASD37-17 TLS encryption between email servers (Limited) ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) ASD37-27 Outbound data loss prevention (Very Good) NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) ISMSP-AC-01 Access Control Policy ISMSP-AC-03 Authentication Mechanisms ISMSP-AC-04 Network Access Control ISMSP-SYS-02 Encryption Implementation ISMSP-SYS-03 Security Monitoring and Log Management CAT-D3-1 Preventative controls CAT-D3-2 Detective controls CAT-D4-3 Third-party access controls CAT-IRP-4 Organizational characteristics UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 23837-1.7.3 Authentication and classical post-processing 27400-6.1 Secure Device Design 27400-6.2 Device Identity and Authentication 27400-7.1 Network Security for IoT 27400-7.4 Data retention and deletion 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats 29115-7.4 Level of Assurance 4 (LoA4) OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-2 Broken Authentication and Token Management OWASPAPI-3 Broken Object Property Level Authorization (BOPLA) OWASPAPI-6 Security Misconfiguration and Secure API Design OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) IM8-CLD.2 Cloud Security Controls IM8-DAT.2 Data Protection IM8-DAT.4 Data Retention and Disposal IM8-SEC.2 Access Control API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-12 Section 62 - Administrative penalties AT-DSG-7 Section 18 - Establishment of the Data Protection Authority FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 62351-14 Cyber security event logging 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures 27010-10.1 Cryptographic Protection 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A34 Request for Correction, Addition or Deletion AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection BB-DPA-1 Section 1 - Short Title BB-DPA-4 Section 4 - Principles Relating to Processing DSO-2 Data Security DSO-3 Data Access Management CJIS-8 Media Protection CJIS-9 System and Communications Protection BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NDPA-1 Applicability, Scope, and Carve-Outs NDPA-4 Sensitive Data Processing Consent and Childrens Protections PAKPDPB-6 Cross-Border Transfer and Data Localization PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security RUSPD-2 Lawful Basis, Consent, Notice RUSPD-4 Special Categories, Biometric Data PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 TURKEYKVKK-2 Information Notice and Data Subject Rights TURKEYKVKK-3 Special Categories and Sensitive Data CPSC-CS.2 Authentication and Access Controls CPSC-CS.3 Data Protection for Safety Systems VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VERMONTAICDA-4 Vermont AG Enforcement and Cure AMLCTF-35 Identity Verification Standard AL-DPA-14 Direct Marketing CA-ITSG33-SC-01 Security Control Catalogue FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ISO-19650-2-5.7 Information model delivery ISO-26000-6.7 Consumer issues ISO28001-PS-01 Facility Security ISO20000-15 Access management for services ISO23894-A.5 Privacy and Data Protection in AI ISO-25012-4.11 Traceability ITIL4-15 Access management for services STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NZISM-3 Personnel Security, Physical Security, and Cryptography NGOB-3 API Security Standards, mTLS, and Encryption EHDSREG-6 Phased Application and Enforcement TEFCAREC-1 Common Agreement Conformance and Onboarding D.1 Incident Response Planning ACE-CR-4 Cargo Release Authorization USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection VIETNAMCYBER-4 Incident Reporting and Cooperation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 322 it maps to, and the evidence behind each claim, over MCP and REST.