R194. Authorize device access to resources


The organization must determine what kind of foreign devices are allowed to consume inner resources.


  1. HIPAA Security Rules 164.310(d)(1): Device and Media Controls: Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of a facility, and the movement of these items within the facility.

  2. NIST 800-53 IA-3 Device identification and authentication: The information system uniquely identifies and authenticates organization-defined devices before establishing a local or remote network connection.

