HIPAA (Security, Privacy and Breach Notification Rules) to NIST SP 800-53 Rev 5 control mapping
HIPAA (Security, Privacy and Breach Notification Rules) maps to 165 NIST SP 800-53 controls in the source dataset. Every one is listed below, with the HIPAA (Security, Privacy and Breach Notification Rules) controls that map to it.
- Shared NIST 800-53 controls
- 165
- HIPAA (Security, Privacy and Breach Notification Rules) controls involved
- 423
- NIST 800-53 families touched
- 20
How this pairing is derived
NIST SP 800-53 Rev 5 is the pivot this whole dataset is built on: every framework in it is mapped to NIST SP 800-53, which is what makes the other pairings on this site derivable at all. This page is the one case where nothing is derived. It lists the authored HIPAA (Security, Privacy and Breach Notification Rules) to NIST SP 800-53 mapping itself, one row per NIST control, so the relationship on each row is the mapping the source states rather than an intersection inferred from two of them.
Shared controls in full
| NIST 800-53 control | Family | HIPAA (Security, Privacy and Breach Notification Rules) controls |
|---|---|---|
| AC-1Policy and Procedures | ACAccess Control | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(2)(ii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| AC-2Account Management | ACAccess Control | 164.308(a)(3)(ii)(C), 164.312(a)(2)(ii) |
| AC-2(2)Automated Temporary and Emergency Account Management | ACAccess Control | 164.312(a)(2)(ii) |
| AC-2(7)Privileged User Accounts | ACAccess Control | 164.308(a)(3)(i), 164.308(a)(3)(ii)(A), 164.308(a)(4)(ii)(C), 164.312(a)(1), 164.514(d)(2)(i)(A), 164.514(d)(2)(i)(B), 164.514(d)(2)(ii), 164.530(c)(2)(ii) |
| AC-2(12)Account Monitoring for Atypical Usage | ACAccess Control | 164.312(b), 164.312(c)(2) |
| AC-3(11)Restrict Access to Specific Information Types | ACAccess Control | 164.308(a)(3)(i), 164.312(c)(2) |
| AC-3(14)Individual Access | ACAccess Control | 164.502(a)(2)(i), 164.502(a)(2)(ii), 164.514(h)(1)(i), 164.514(h)(1)(ii), 164.524(a)(1), 164.524(a)(1)(i), 164.524(a)(1)(ii), 164.524(a)(1)(iii), 164.524(a)(1)(iii)(A), 164.524(a)(1)(iii)(B), 164.524(a)(2), 164.524(a)(2)(i), 164.524(a)(2)(ii), 164.524(a)(2)(iii), 164.524(a)(2)(iv), 164.524(a)(2)(v), 164.524(a)(3), 164.524(a)(3)(i), 164.524(a)(3)(ii), 164.524(a)(3)(iii), 164.524(a)(4), 164.524(b)(1), 164.524(b)(2)(i), 164.524(b)(2)(i)(A), 164.524(b)(2)(i)(B), 164.524(b)(2)(ii), 164.524(b)(2)(ii)(A), 164.524(b)(2)(ii)(B), 164.524(c), 164.524(c)(1), 164.524(c)(3)(i), 164.524(c)(3)(ii), 164.524(c)(4), 164.524(c)(4)(i), 164.524(c)(4)(ii), 164.524(c)(4)(iii), 164.524(c)(4)(iv), 164.524(d), 164.524(d)(1), 164.524(d)(2) |
| AC-6Least Privilege | ACAccess Control | 164.308(a)(3)(i), 164.312(a)(1) |
| AC-6(7)Review of User Privileges | ACAccess Control | 164.308(a)(3)(ii)(B) |
| AC-12Session Termination | ACAccess Control | 164.312(a)(2)(iii) |
| AC-20(2)Portable Storage Devices — Restricted Use | ACAccess Control | 164.310(d)(1) |
| AC-20(5)Portable Storage Devices — Prohibited Use | ACAccess Control | 164.310(d)(1) |
| AC-21Information Sharing | ACAccess Control | 164.506(c)(1), 164.506(c)(2), 164.506(c)(3), 164.506(c)(4), 164.508(a)(1), 164.508(a)(4)(i) |
| AC-23Data Mining Protection | ACAccess Control | 164.502(c), 164.502(d)(1), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c) |
| AC-24Access Control Decisions | ACAccess Control | 164.308(a)(3)(ii)(A) |
| AT-1Policy and Procedures | ATAwareness and Training | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(5)(i), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| AT-2Literacy Training and Awareness | ATAwareness and Training | 164.308(a)(5)(i), 164.530(b)(2)(i), 164.530(b)(2)(i)(A), 164.530(b)(2)(i)(B), 164.530(b)(2)(i)(C), 164.530(b)(2)(ii) |
| AT-2(4)Suspicious Communications and Anomalous System Behavior | ATAwareness and Training | 164.308(a)(5)(ii)(B) |
| AT-2(5)Advanced Persistent Threat | ATAwareness and Training | 164.308(a)(5)(ii)(B) |
| AT-2(6)Cyber Threat Environment | ATAwareness and Training | 164.308(a)(5)(ii)(A) |
| AT-3Role-based Training | ATAwareness and Training | 164.308(a)(5)(ii)(C), 164.308(a)(5)(ii)(D), 164.530(b)(1) |
| AT-3(2)Physical Security Controls | ATAwareness and Training | 164.308(a)(5)(ii)(C), 164.308(a)(5)(ii)(D), 164.530(b)(1) |
| AU-1Policy and Procedures | AUAudit and Accountability | 164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(b), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| AU-2Event Logging | AUAudit and Accountability | 164.308(a)(1)(ii)(D), 164.312(b) |
| AU-3Content of Audit Records | AUAudit and Accountability | 164.312(b) |
| CA-1Policy and Procedures | CAAssessment, Authorization, and Monitoring | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| CA-2Control Assessments | CAAssessment, Authorization, and Monitoring | 164.306(d)(3)(i), 164.306(e), 164.308(a)(8), 164.316(b)(1) |
| CA-7Continuous Monitoring | CAAssessment, Authorization, and Monitoring | 164.306(d)(3)(i), 164.316(b)(2)(iii) |
| CA-7(1)Independent Assessment | CAAssessment, Authorization, and Monitoring | 164.306(d)(3)(i), 164.316(b)(2)(iii) |
| CM-1Policy and Procedures | CMConfiguration Management | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| CM-2Baseline Configuration | CMConfiguration Management | 164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii) |
| CM-3Configuration Change Control | CMConfiguration Management | 164.308(a)(1)(i) |
| CM-6Configuration Settings | CMConfiguration Management | 164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii) |
| CM-8System Component Inventory | CMConfiguration Management | 164.310(d)(2)(iii) |
| CM-8(1)Updates During Installation and Removal | CMConfiguration Management | 164.310(d)(2)(iii) |
| CM-8(2)Automated Maintenance | CMConfiguration Management | 164.310(d)(2)(iii) |
| CM-8(4)Accountability Information | CMConfiguration Management | 164.310(d)(2)(iii) |
| CM-8(7)Centralized Repository | CMConfiguration Management | 164.310(d)(2)(iii) |
| CM-9Configuration Management Plan | CMConfiguration Management | 164.308(a)(1)(i) |
| CP-1Policy and Procedures | CPContingency Planning | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.308(a)(7)(ii)(C), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| CP-2Contingency Plan | CPContingency Planning | 164.308(a)(7)(i), 164.308(a)(7)(ii)(C) |
| CP-2(5)Continue Mission and Business Functions | CPContingency Planning | 164.308(a)(7)(ii)(C) |
| CP-2(8)Identify Critical Assets | CPContingency Planning | 164.308(a)(7)(ii)(E) |
| CP-4Contingency Plan Testing | CPContingency Planning | 164.308(a)(7)(ii)(D) |
| CP-7(2)Accessibility | CPContingency Planning | 164.310(a)(2)(i) |
| CP-9System Backup | CPContingency Planning | 164.308(a)(7)(ii)(A), 164.310(d)(2)(iv) |
| CP-10System Recovery and Reconstitution | CPContingency Planning | 164.308(a)(7)(i), 164.308(a)(7)(ii)(B), 164.308(a)(7)(ii)(C) |
| IA-1Policy and Procedures | IAIdentification and Authentication | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(2)(ii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| IA-2Identification and Authentication (Organizational Users) | IAIdentification and Authentication | 164.312(a)(2)(i) |
| IA-4Identifier Management | IAIdentification and Authentication | 164.312(a)(2)(i) |
| IA-12Identity Proofing | IAIdentification and Authentication | 164.312(d) |
| IA-12(1)Supervisor Authorization | IAIdentification and Authentication | 164.308(a)(3)(ii)(A) |
| IA-12(2)Identity Evidence | IAIdentification and Authentication | 164.312(d) |
| IA-12(3)Identity Evidence Validation and Verification | IAIdentification and Authentication | 164.312(d) |
| IA-12(4)In-person Validation and Verification | IAIdentification and Authentication | 164.308(a)(3)(ii)(C) |
| IR-1Policy and Procedures | IRIncident Response | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| IR-4Incident Handling | IRIncident Response | 164.308(a)(6)(ii), 164.412, 164.412(a), 164.412(b), 164.530(f) |
| IR-4(3)Continuity of Operations | IRIncident Response | 164.308(a)(7)(i), 164.308(a)(7)(ii)(C) |
| IR-4(13)Behavior Analysis | IRIncident Response | 164.312(b), 164.312(c)(2) |
| IR-5Incident Monitoring | IRIncident Response | 164.308(a)(1)(ii)(D) |
| IR-6Incident Reporting | IRIncident Response | 164.404(b), 164.408(a), 164.408(b), 164.408(c) |
| IR-8(1)Breaches | IRIncident Response | 164.404(a)(1), 164.404(a)(2), 164.404(c)(1)(A), 164.404(c)(1)(B), 164.404(c)(1)(C), 164.404(c)(1)(D), 164.404(c)(1)(E), 164.404(c)(2), 164.404(d)(1)(i), 164.404(d)(1)(ii), 164.404(d)(2), 164.404(d)(2)(i), 164.404(d)(2)(ii)(A), 164.404(d)(2)(ii)(B), 164.404(d)(3), 164.406(a), 164.406(b), 164.406(c), 164.410(c)(1) |
| MA-1Policy and Procedures | MAMaintenance | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| MA-2Controlled Maintenance | MAMaintenance | 164.310(a)(2)(iv) |
| MA-3(3)Prevent Unauthorized Removal | MAMaintenance | 164.310(d)(1) |
| PE-1Policy and Procedures | PEPhysical and Environmental Protection | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| PE-2Physical Access Authorizations | PEPhysical and Environmental Protection | 164.310(a)(2)(i), 164.310(a)(2)(iii) |
| PE-2(1)Access by Position or Role | PEPhysical and Environmental Protection | 164.310(a)(2)(i) |
| PE-3Physical Access Control | PEPhysical and Environmental Protection | 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(c) |
| PE-3(1)System Access | PEPhysical and Environmental Protection | 164.310(b), 164.310(c) |
| PE-3(2)Facility and Systems | PEPhysical and Environmental Protection | 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(c) |
| PE-3(3)Continuous Guards | PEPhysical and Environmental Protection | 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(c) |
| PE-23Facility Location | PEPhysical and Environmental Protection | 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv) |
| PL-1Policy and Procedures | PLPlanning | 164.306(c), 164.306(d)(1), 164.306(d)(2), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.314(a)(1), 164.314(a)(2)(ii), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.504(g)(1), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| PL-4Rules of Behavior | PLPlanning | 164.310(b) |
| PL-8Security and Privacy Architectures | PLPlanning | 164.306(b)(1), 164.306(b)(2)(ii) |
| PL-8(1)Defense in Depth | PLPlanning | 164.306(b)(1) |
| PL-9Central Management | PLPlanning | 164.308(a)(2) |
| PL-10Baseline Selection | PLPlanning | 164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii) |
| RA-1Policy and Procedures | RARisk Assessment | 164.306(a)(3), 164.306(b)(2)(iv), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| RA-2Security Categorization | RARisk Assessment | 164.306(b)(2)(iv) |
| RA-3Risk Assessment | RARisk Assessment | 164.306(b)(2)(iv), 164.306(d)(3)(i), 164.306(e), 164.308(a)(1)(ii)(A), 164.308(a)(8) |
| RA-9Criticality Analysis | RARisk Assessment | 164.306(b)(2)(ii), 164.308(a)(7)(ii)(E) |
| SA-1Policy and Procedures | SASystem and Services Acquisition | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| SA-2Allocation of Resources | SASystem and Services Acquisition | 164.306(b)(2)(iii) |
| SA-4Acquisition Process | SASystem and Services Acquisition | 164.308(b)(1), 164.312(d) |
| SA-4(12)Data Ownership | SASystem and Services Acquisition | 164.310(d)(2)(iii) |
| SA-8Security and Privacy Engineering Principles | SASystem and Services Acquisition | 164.306(b)(1), 164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii) |
| SA-8(14)Least Privilege | SASystem and Services Acquisition | 164.308(a)(3)(i), 164.312(a)(1) |
| SA-8(32)Sufficient Documentation | SASystem and Services Acquisition | 164.310(b), 164.316(b)(2)(ii) |
| SA-9External System Services | SASystem and Services Acquisition | 164.308(b)(1) |
| SA-9(3)Establish and Maintain Trust Relationship with Providers | SASystem and Services Acquisition | 164.308(a)(7)(ii)(E), 164.308(b)(1), 164.504(e)(2)(iii) |
| SA-15(5)Attack Surface Reduction | SASystem and Services Acquisition | 164.306(b)(1), 164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii) |
| SC-1Policy and Procedures | SCSystem and Communications Protection | 164.306(b)(1), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(e)(1), 164.312(e)(2)(i), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| SC-3(5)Layered Structures | SCSystem and Communications Protection | 164.306(b)(1) |
| SC-7(18)Fail Secure | SCSystem and Communications Protection | 164.306(b)(1) |
| SC-8Transmission Confidentiality and Integrity | SCSystem and Communications Protection | 164.312(e)(1), 164.312(e)(2)(i) |
| SC-8(1)Cryptographic Protection | SCSystem and Communications Protection | 164.312(a)(2)(iv), 164.312(e)(1), 164.312(e)(2)(ii) |
| SC-8(2)Pre- and Post-transmission Handling | SCSystem and Communications Protection | 164.312(a)(2)(iv), 164.312(e)(2)(ii) |
| SC-13Cryptographic Protection | SCSystem and Communications Protection | 164.312(a)(2)(iv), 164.312(e)(2)(ii) |
| SC-16(1)Integrity Verification | SCSystem and Communications Protection | 164.312(e)(2)(i) |
| SC-28Protection of Information at Rest | SCSystem and Communications Protection | 164.310(c) |
| SC-28(1)Cryptographic Protection | SCSystem and Communications Protection | 164.312(e)(2)(i) |
| SC-28(2)Offline Storage | SCSystem and Communications Protection | 164.308(a)(7)(ii)(A), 164.310(d)(2)(iv) |
| SI-1Policy and Procedures | SISystem and Information Integrity | 164.306(b)(1), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| SI-4System Monitoring | SISystem and Information Integrity | 164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.312(b) |
| SI-4(5)System-generated Alerts | SISystem and Information Integrity | 164.312(b) |
| SI-4(11)Analyze Communications Traffic Anomalies | SISystem and Information Integrity | 164.312(b), 164.312(c)(2) |
| SI-4(20)Privileged Users | SISystem and Information Integrity | 164.312(c)(2) |
| SI-4(24)Indicators of Compromise | SISystem and Information Integrity | 164.312(c)(2) |
| SI-7(6)Cryptographic Protection | SISystem and Information Integrity | 164.312(a)(2)(iv), 164.312(e)(2)(ii) |
| SI-12Information Management and Retention | SISystem and Information Integrity | 164.316(b)(2)(i), 164.530(j)(2) |
| SI-12(1)Limit Personally Identifiable Information Elements | SISystem and Information Integrity | 164.502(b)(1), 164.508(a)(2)(i)(B) |
| SI-12(2)Minimize Personally Identifiable Information in Testing, Training, and Research | SISystem and Information Integrity | 164.508(a)(2)(i)(B) |
| SI-18(4)Individual Requests | SISystem and Information Integrity | 164.502(a)(2)(i), 164.502(a)(2)(ii), 164.514(h)(1)(i), 164.514(h)(1)(ii), 164.524(a)(1), 164.524(a)(1)(i), 164.524(a)(1)(ii), 164.524(a)(1)(iii), 164.524(a)(1)(iii)(A), 164.524(a)(1)(iii)(B), 164.524(a)(2), 164.524(a)(2)(i), 164.524(a)(2)(ii), 164.524(a)(2)(iii), 164.524(a)(2)(iv), 164.524(a)(2)(v), 164.524(a)(3), 164.524(a)(3)(i), 164.524(a)(3)(ii), 164.524(a)(3)(iii), 164.524(a)(4), 164.524(b)(1), 164.524(b)(2)(i), 164.524(b)(2)(i)(A), 164.524(b)(2)(i)(B), 164.524(b)(2)(ii), 164.524(b)(2)(ii)(A), 164.524(b)(2)(ii)(B), 164.524(c), 164.524(c)(1), 164.524(c)(3)(i), 164.524(c)(3)(ii), 164.524(c)(4), 164.524(c)(4)(i), 164.524(c)(4)(ii), 164.524(c)(4)(iii), 164.524(c)(4)(iv), 164.524(d), 164.524(d)(1), 164.524(d)(2), 164.526(a)(1), 164.526(a)(2), 164.526(a)(2)(i), 164.526(a)(2)(ii), 164.526(a)(2)(iii), 164.526(a)(2)(iv), 164.526(b)(1) |
| SI-18(5)Notice of Correction or Deletion | SISystem and Information Integrity | 164.526(a)(1), 164.526(a)(2), 164.526(a)(2)(i), 164.526(a)(2)(ii), 164.526(a)(2)(iii), 164.526(a)(2)(iv), 164.526(b)(1), 164.526(c), 164.526(c)(1), 164.526(c)(2), 164.526(c)(3), 164.526(c)(3)(i), 164.526(c)(3)(ii) |
| MP-1Policy and Procedures | MPMedia Protection | 164.306(a)(3), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.514(d)(3)(i), 164.530(c)(2)(i), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| MP-2Media Access | MPMedia Protection | 164.310(b), 164.310(d)(1) |
| MP-5Media Transport | MPMedia Protection | 164.310(d)(1) |
| MP-5(3)Custodians | MPMedia Protection | 164.310(d)(1) |
| MP-6Media Sanitization | MPMedia Protection | 164.310(d)(2)(ii) |
| MP-6(3)Nondestructive Techniques | MPMedia Protection | 164.310(d)(2)(ii) |
| MP-7Media Use | MPMedia Protection | 164.316(b)(2)(i), 164.530(j)(2) |
| PS-1Policy and Procedures | PSPersonnel Security | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(3)(ii)(A), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(d), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(e)(2), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| PS-2Position Risk Designation | PSPersonnel Security | 164.308(a)(3)(ii)(B), 164.312(a)(1), 164.530(a)(2) |
| PS-3Personnel Screening | PSPersonnel Security | 164.312(d) |
| PS-4Personnel Termination | PSPersonnel Security | 164.308(a)(3)(ii)(C) |
| PS-5Personnel Transfer | PSPersonnel Security | 164.308(a)(3)(ii)(C) |
| PS-6Access Agreements | PSPersonnel Security | 164.502(a) |
| PS-6(2)Classified Information Requiring Special Protection | PSPersonnel Security | 164.502(a) |
| PS-8Personnel Sanctions | PSPersonnel Security | 164.308(a)(1)(ii)(C), 164.530(e)(1) |
| PS-9Position Descriptions | PSPersonnel Security | 164.308(a)(3)(ii)(B), 164.310(a)(2)(i), 164.312(a)(1), 164.530(a)(2) |
| PM-1Information Security Program Plan | PMProgram Management | 164.306(a)(1), 164.306(a)(2), 164.306(a)(3), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(1), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| PM-2Information Security Program Leadership Role | PMProgram Management | 164.308(a)(2) |
| PM-5System Inventory | PMProgram Management | 164.308(a)(7)(ii)(E), 164.310(d)(1), 164.310(d)(2)(i), 164.310(d)(2)(iii) |
| PM-6Measures of Performance | PMProgram Management | 164.308(a)(2) |
| PM-7Enterprise Architecture | PMProgram Management | 164.306(b)(1), 164.306(b)(2)(ii) |
| PM-8Critical Infrastructure Plan | PMProgram Management | 164.306(c), 164.306(d)(1), 164.306(d)(2), 164.308(a)(7)(i), 164.308(a)(7)(ii)(C), 164.314(a)(1), 164.314(a)(2)(ii), 164.504(g)(1), 164.530(i)(1) |
| PM-9Risk Management Strategy | PMProgram Management | 164.306(a)(3), 164.306(b)(2)(iv) |
| PM-11Mission and Business Process Definition | PMProgram Management | 164.306(b)(2)(i) |
| PM-13Security and Privacy Workforce | PMProgram Management | 164.308(a)(3)(ii)(B), 164.308(a)(5)(i), 164.310(a)(2)(i), 164.312(a)(1), 164.530(a)(2) |
| PM-14Testing, Training, and Monitoring | PMProgram Management | 164.306(d)(3)(i), 164.316(b)(2)(iii) |
| PM-18Privacy Program Plan | PMProgram Management | 164.502(a), 164.530(a)(1)(i), 164.530(i)(1), 164.530(i)(4)(i)(A), 164.530(i)(4)(i)(B), 164.530(i)(5), 164.530(i)(5)(i), 164.530(i)(5)(ii) |
| PM-19Privacy Program Leadership Role | PMProgram Management | 164.530(a)(1)(i) |
| PM-20(1)Privacy Policies on Websites, Applications, and Digital Services | PMProgram Management | 164.520(a)(1), 164.520(a)(2)(i), 164.520(a)(2)(i)(A), 164.520(a)(2)(i)(B), 164.520(a)(2)(ii), 164.520(a)(2)(ii)(A), 164.520(a)(2)(ii)(B), 164.520(a)(2)(iii), 164.520(b)(1), 164.520(b)(1)(i), 164.520(b)(1)(ii), 164.520(b)(1)(ii)(A), 164.520(b)(1)(ii)(B), 164.520(b)(1)(ii)(C), 164.520(b)(1)(ii)(D), 164.520(b)(1)(ii)(E), 164.520(b)(1)(iv), 164.520(b)(1)(iv)(A), 164.520(b)(1)(iv)(B), 164.520(b)(1)(iv)(C), 164.520(b)(1)(iv)(D), 164.520(b)(1)(iv)(E), 164.520(b)(1)(iv)(F), 164.520(b)(1)(v), 164.520(b)(1)(v)(A), 164.520(b)(1)(v)(B), 164.520(b)(1)(v)(C), 164.520(b)(1)(vi), 164.520(b)(1)(vii), 164.520(b)(1)(viii), 164.520(b)(2)(i), 164.520(b)(2)(ii), 164.520(b)(3), 164.520(c), 164.520(c)(1)(i), 164.520(c)(1)(i)(A), 164.520(c)(1)(i)(B), 164.520(c)(1)(ii), 164.520(c)(1)(iii), 164.520(c)(1)(iv), 164.520(c)(1)(v), 164.520(c)(1)(v)(A), 164.520(c)(1)(v)(B), 164.530(i)(4)(i)(C) |
| PM-21Accounting of Disclosures | PMProgram Management | 164.528(a)(1), 164.528(a)(1)(i), 164.528(a)(1)(ii), 164.528(a)(1)(iii), 164.528(a)(1)(iv), 164.528(a)(1)(ix), 164.528(a)(1)(v), 164.528(a)(1)(vi), 164.528(a)(1)(vii), 164.528(a)(1)(viii), 164.528(b), 164.528(b)(1), 164.528(b)(2), 164.528(b)(2)(i), 164.528(b)(2)(ii), 164.528(b)(2)(iii), 164.528(b)(2)(iv), 164.528(b)(3), 164.528(b)(3)(i), 164.528(b)(3)(ii), 164.528(b)(3)(iii), 164.528(b)(4)(i), 164.528(b)(4)(i)(A), 164.528(b)(4)(i)(B), 164.528(b)(4)(i)(C), 164.528(b)(4)(i)(D), 164.528(b)(4)(i)(E), 164.528(b)(4)(i)(F), 164.528(b)(4)(ii), 164.528(c)(1), 164.528(c)(1)(i), 164.528(c)(1)(ii), 164.528(c)(1)(ii)(A), 164.528(c)(1)(ii)(B), 164.528(c)(2), 164.528(d), 164.528(d)(1), 164.528(d)(2), 164.528(d)(3) |
| PM-22Personally Identifiable Information Quality Management | PMProgram Management | 164.512(i)(1)(i)(B), 164.512(i)(1)(i)(B)(1), 164.512(i)(1)(i)(B)(2), 164.512(i)(1)(i)(B)(3) |
| PM-23Data Governance Body | PMProgram Management | 164.512(i)(1)(i)(B), 164.512(i)(1)(i)(B)(1), 164.512(i)(1)(i)(B)(2), 164.512(i)(1)(i)(B)(3) |
| PM-24Data Integrity Board | PMProgram Management | 164.512(i)(1)(i)(B), 164.512(i)(1)(i)(B)(1), 164.512(i)(1)(i)(B)(2), 164.512(i)(1)(i)(B)(3) |
| PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and Research | PMProgram Management | 164.502(c), 164.502(d)(1), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(B), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c) |
| PM-26Complaint Management | PMProgram Management | 164.524(d)(4), 164.526(b)(2)(i), 164.526(b)(2)(i)(A), 164.526(b)(2)(i)(B), 164.526(b)(2)(ii), 164.526(b)(2)(ii)(A), 164.526(b)(2)(ii)(B), 164.526(d), 164.526(d)(1), 164.526(d)(1)(i), 164.526(d)(1)(ii), 164.526(d)(1)(iii), 164.526(d)(1)(iv), 164.526(d)(2), 164.526(d)(3), 164.526(d)(4), 164.526(d)(5)(i), 164.526(d)(5)(ii), 164.526(d)(5)(iii), 164.526(e), 164.526(f), 164.530(d)(1), 164.530(d)(2) |
| PM-28Risk Framing | PMProgram Management | 164.306(b)(2)(iv) |
| PM-29Risk Management Program Leadership Roles | PMProgram Management | 164.306(a)(3), 164.306(b)(2)(iv), 164.308(a)(2) |
| PM-30(1)Suppliers of Critical or Mission-essential Items | PMProgram Management | 164.308(a)(7)(ii)(E) |
| PM-31Continuous Monitoring Strategy | PMProgram Management | 164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.312(b) |
| PT-1Policy and Procedures | PTPII Processing and Transparency | 164.306(b)(1), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.502(a), 164.530(a)(1)(i), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(i)(4)(i)(A), 164.530(i)(4)(i)(B), 164.530(i)(5), 164.530(i)(5)(i), 164.530(i)(5)(ii), 164.530(j)(1)(i) |
| PT-2Authority to Process Personally Identifiable Information | PTPII Processing and Transparency | 164.502(a)(1)(i), 164.502(a)(1)(ii), 164.502(a)(1)(iii), 164.502(a)(5)(i), 164.502(c), 164.502(d)(1), 164.502(i), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(B), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c) |
| PT-3Personally Identifiable Information Processing Purposes | PTPII Processing and Transparency | 164.502(a)(3), 164.508(a)(2)(i)(B), 164.508(c)(1)(i), 164.508(c)(1)(ii), 164.508(c)(1)(iii), 164.508(c)(1)(iv), 164.508(c)(2)(i)(A), 164.508(c)(2)(i)(B) |
| PT-4Consent | PTPII Processing and Transparency | 164.506(b)(1), 164.508(a)(2), 164.508(c)(1)(v), 164.508(c)(3), 164.510(b)(2)(i), 164.510(b)(2)(ii), 164.510(b)(2)(iii), 164.510(b)(3), 164.514(f)(2)(ii), 164.514(f)(2)(iv), 164.514(f)(2)(v) |
| PT-5Privacy Notice | PTPII Processing and Transparency | 164.520(a)(1), 164.520(a)(2)(i), 164.520(a)(2)(i)(A), 164.520(a)(2)(i)(B), 164.520(a)(2)(ii), 164.520(a)(2)(ii)(A), 164.520(a)(2)(ii)(B), 164.520(a)(2)(iii), 164.520(b)(1), 164.520(b)(1)(i), 164.520(b)(1)(ii), 164.520(b)(1)(ii)(A), 164.520(b)(1)(ii)(B), 164.520(b)(1)(ii)(C), 164.520(b)(1)(ii)(D), 164.520(b)(1)(ii)(E), 164.520(b)(1)(iv), 164.520(b)(1)(iv)(A), 164.520(b)(1)(iv)(B), 164.520(b)(1)(iv)(C), 164.520(b)(1)(iv)(D), 164.520(b)(1)(iv)(E), 164.520(b)(1)(iv)(F), 164.520(b)(1)(v), 164.520(b)(1)(v)(A), 164.520(b)(1)(v)(B), 164.520(b)(1)(v)(C), 164.520(b)(1)(vi), 164.520(b)(1)(vii), 164.520(b)(1)(viii), 164.520(b)(2)(i), 164.520(b)(2)(ii), 164.520(b)(3), 164.520(c), 164.520(c)(1)(i), 164.520(c)(1)(i)(A), 164.520(c)(1)(i)(B), 164.520(c)(1)(ii), 164.520(c)(1)(iii), 164.520(c)(1)(iv), 164.520(c)(1)(v), 164.520(c)(1)(v)(A), 164.520(c)(1)(v)(B), 164.530(i)(4)(i)(C) |
| PT-7Specific Categories of Personally Identifiable Information | PTPII Processing and Transparency | 164.502(c), 164.502(d)(1), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c) |
| SR-1Policy and Procedures | SRSupply Chain Risk Management | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.308(b)(1), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(d), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) |
| SR-3(3)Sub-tier Flow Down | SRSupply Chain Risk Management | 164.308(b)(1), 164.308(b)(2), 164.308(b)(3), 164.314(a)(2)(i), 164.314(a)(2)(iii), 164.314(b)(1), 164.314(b)(2), 164.502(a)(4)(i), 164.502(a)(4)(ii), 164.502(e)(1)(i), 164.502(e)(1)(ii), 164.502(e)(2), 164.504(e)(2)(i), 164.504(e)(2)(i)(A), 164.504(e)(2)(i)(B), 164.504(e)(2)(ii)(D), 164.504(e)(2)(ii)(J), 164.504(e)(4)(i)(B)(ii)(B)(1), 164.504(e)(4)(i)(B)(ii)(B)(2), 164.504(f)(1)(i), 164.504(f)(2)(i), 164.504(f)(2)(ii), 164.504(f)(2)(ii)(A), 164.504(f)(2)(ii)(B), 164.504(f)(2)(ii)(C), 164.504(f)(2)(ii)(D), 164.504(f)(2)(ii)(E), 164.504(f)(2)(ii)(F), 164.504(f)(2)(ii)(G), 164.504(f)(2)(ii)(H), 164.504(f)(2)(ii)(I), 164.504(f)(2)(ii)(J), 164.504(f)(2)(iii)(A), 164.504(f)(2)(iii)(B), 164.504(f)(2)(iii)(C), 164.504(f)(3)(i), 164.504(f)(3)(ii), 164.504(f)(3)(iii), 164.504(f)(3)(iv) |
| SR-8Notification Agreements | SRSupply Chain Risk Management | 164.314(a)(2)(i), 164.314(b)(2), 164.410(a)(1), 164.410(a)(2), 164.410(b), 164.410(c)(2) |
| SR-12Component Disposal | SRSupply Chain Risk Management | 164.310(d)(2)(i), 164.310(d)(2)(ii) |
Source and method
Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.
Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.
Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.
Related pairings
- PCI DSS v4.0.1 to NIST SP 800-53 Rev 5 control mapping326 shared controls
- SOC 2 Type II to NIST SP 800-53 Rev 5 control mapping301 shared controls
- NIST CSF 2.0 to NIST SP 800-53 Rev 5 control mapping233 shared controls
- CMMC Level 2 to NIST SP 800-53 Rev 5 control mapping218 shared controls
- NIST SP 800-171 Rev 2 to NIST SP 800-53 Rev 5 control mapping218 shared controls
- SOC 2 Type II to HIPAA (Security, Privacy and Breach Notification Rules) control mapping132 shared controls