164.316(b)(2)(iii) Updates (Documentation)
164.316(b)(2)(iii) in HIPAA Security Rule (the HIPAA Security Rule as it currently stands). All HIPAA Security Rule controls held. Open HIPAA Security Rule on the standards site.
The control as we hold it
Updates (Documentation). Review documentation periodically, and update as needed, in response to environmental or operational changes affecting the security of ePHI.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9) (closest match)
- SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12) (closest match)
- SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure (closest match)
NIST SP 800-53 Rev 5
- NIST800-CA-5 CA-5 Plan of Action and Milestones (closest match)
- NIST800-CM-9 CM-9 Configuration Management Plan (closest match)
- NIST800-PL-1 PL-1 Policy and Procedures (closest match)
- NIST800-PL-7 PL-7 Concept of Operations (closest match)
- NIST800-PM-4 PM-4 Plan of Action and Milestones Process (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: Policies and Procedures), in our words, not a statement of the standard and not binding on an assessor.
- the current security policies and procedures
- the review and update record with dates
- the documentation-retention record