164.310(d)(2)(iii) Accountability (Addressable)
164.310(d)(2)(iii) in HIPAA Security Rule (the HIPAA Security Rule as it currently stands). All HIPAA Security Rule controls held. Open HIPAA Security Rule on the standards site.
The control as we hold it
Accountability (Addressable). Maintain a record of the movements of hardware and electronic media containing ePHI and any person responsible. NIST recommends asset tagging, custody logs, and reconciliation.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets (closest match)
- SOC2-CC6.5 CC6.5 Protecting data on assets until disposal (closest match)
- SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal (closest match)
- SOC2-P6.2 P6.2 Record of authorised disclosures (closest match)
- SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches (closest match)
NIST SP 800-53 Rev 5
- NIST800-CM-8 CM-8 System Component Inventory (closest match)
- NIST800-MP-5 MP-5 Media Transport (closest match)
- NIST800-PE-16 PE-16 Delivery and Removal (closest match)
- NIST800-PE-20 PE-20 Asset Monitoring and Tracking (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: Physical), in our words, not a statement of the standard and not binding on an assessor.
- the facility access and visitor records
- the workstation-use and device-control records
- the media-disposal and re-use records