164.316(b)(1) Documentation (Standard)
164.316(b)(1) in HIPAA Security Rule (the HIPAA Security Rule as it currently stands). All HIPAA Security Rule controls held. Open HIPAA Security Rule on the standards site.
The control as we hold it
Documentation (Standard). Maintain the policies and procedures and a written or electronic record of any required action, activity, or assessment. NIST recommends document management platform with controlled retention.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17) (closest match)
- SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12) (closest match)
- SOC2-CC6.5 CC6.5 Protecting data on assets until disposal (closest match)
- SOC2-P6.2 P6.2 Record of authorised disclosures (closest match)
- SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches (closest match)
NIST SP 800-53 Rev 5
- NIST800-AT-4 AT-4 Training Records (closest match)
- NIST800-AU-11 AU-11 Audit Record Retention (closest match)
- NIST800-CA-5 CA-5 Plan of Action and Milestones (closest match)
- NIST800-PL-1 PL-1 Policy and Procedures (closest match)
- NIST800-PL-2 PL-2 System Security and Privacy Plans (closest match)
- NIST800-PM-21 PM-21 Accounting of Disclosures (closest match)
- NIST800-PM-28 PM-28 Risk Framing (closest match)
- NIST800-SA-5 SA-5 System Documentation (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: Policies and Procedures), in our words, not a statement of the standard and not binding on an assessor.
- the current security policies and procedures
- the review and update record with dates
- the documentation-retention record