New SIEM admin
Analyst promoted to detection engineering receives SIEM admin only after CISO designee approves AC-6(1) authorization — not via informal Slack ask.
AC-6(1) requires authorizing access to organization-defined security functions and security-relevant information. Unlike general least privilege, this enhancement forces an explicit authorization step for security functions — audit administration, authentication policy, cryptographic controls, and access-control administration on systems that protect ePHI. Informal 'IT can do everything' fails this control.
Grant access to security functions only through documented authorization so the set of people who can change ePHI protections stays intentional and minimal.
How this control shows up in healthcare and HIPAA-covered environments.
Analyst promoted to detection engineering receives SIEM admin only after CISO designee approves AC-6(1) authorization — not via informal Slack ask.
Only three named security engineers hold the role; each annual recert lists business justification tied to job duties.
Subscription-level IAM rights to the PHI analytics project require security authorization distinct from general DevOps contributor rights.
Who can turn off logging or change MFA policy is a favorite assessor question. Missing authorization evidence for those roles is an AC-6(1) failure.
How this NIST control supports HIPAA Security Rule expectations.
Pure content config may not be; anything affecting authN/authZ/audit/crypto is.
Yes with BAA, named users, authorization, and monitoring — not shared generic logins.
AC-3(1) restricts privileged functions technically; AC-6(1) emphasizes authorizing who gets security-function access under least privilege.
Related controls that commonly accompany AC-6(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.