Skip to content

HIPAANIST CSF 2.0 crosswalk

A control-by-control mapping between HIPAA Security Rule (45 CFR Part 164, Subpart C) and NIST Cybersecurity Framework 2.0. 7 mappings.

HIPAANIST CSF 2.0RelationshipNotes
§164.308(a)(1)
Security management process
ID.RA-01
Vulnerabilities identified and recorded
RelatedCurated
Risk assessment & management
§164.312(a)(1)
Access control
PR.AA-01
Identities and credentials managed
EquivalentCurated
Access control & identity
§164.312(a)(1)
Access control
PR.AA-05
Access permissions and authorizations enforced
EquivalentCurated
Access control & identity
§164.312(b)
Audit controls
DE.CM-01
Networks and services monitored
EquivalentCurated
Logging, monitoring & detection
§164.312(b)
Audit controls
PR.PS-04
Log records generated for monitoring
EquivalentCurated
Logging, monitoring & detection
§164.312(e)(1)
Transmission security
PR.DS-01
Confidentiality of data-at-rest protected
EquivalentCurated
Cryptography & data protection
§164.312(e)(1)
Transmission security
PR.DS-02
Confidentiality of data-in-transit protected
EquivalentCurated
Cryptography & data protection

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.