164.308(a)(8) Evaluation (Standard)
164.308(a)(8) in HIPAA Security Rule (the HIPAA Security Rule as it currently stands). All HIPAA Security Rule controls held. Open HIPAA Security Rule on the standards site.
The control as we hold it
Evaluation (Standard). Perform periodic technical and nontechnical evaluation. NIST recommends combining policy review, control testing, vulnerability assessments, and audits to evaluate ongoing compliance.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9) (closest match)
- SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) (closest match)
- SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17) (closest match)
- SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities (closest match)
NIST SP 800-53 Rev 5
- NIST800-AU-6 AU-6 Audit Record Review, Analysis, and Reporting (closest match)
- NIST800-CA-2 CA-2 Control Assessments (closest match)
- NIST800-CA-7 CA-7 Continuous Monitoring (closest match)
- NIST800-PM-4 PM-4 Plan of Action and Milestones Process (closest match)
- NIST800-PM-31 PM-31 Continuous Monitoring Strategy (closest match)
- NIST800-RA-5 RA-5 Vulnerability Monitoring and Scanning (closest match)
- NIST800-SI-18 SI-18 Personally Identifiable Information Quality Operations (closest match)
- NIST800-SI-19 SI-19 De-identification (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: Administrative), in our words, not a statement of the standard and not binding on an assessor.
- the risk analysis and risk-management records
- the workforce clearance, training and sanction records
- the access-authorisation and termination records
- the contingency-plan test and evaluation records