International (ISO/TC 215)

ISO 27799:2025

130 controls. 220 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

130 controls 220 frameworks share controls with it International (ISO/TC 215) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
ISO27799-01ePHI access controls and authorization122
ISO27799-02ePHI encryption at rest and in transit112
ISO27799-03Minimum necessary standard enforcement89
ISO27799-04Patient data de-identification procedures89
ISO27799-05Audit trail for ePHI access121
ISO27799-06Security management process and risk analysis123
ISO27799-07Workforce security and clearance procedures12
ISO27799-08Information access management98
ISO27799-09Security awareness and training program23
ISO27799-10Contingency planning for ePHI0
ISO27799-10.1Operational Procedures for Clinical Systems0
ISO27799-10.2Backup of Health Records0
ISO27799-10.3Audit Logging in Clinical Systems0
ISO27799-10.4Anti-malware on Clinical Endpoints0
ISO27799-11Business associate management0
ISO27799-11.1Access Control to Health Records1
ISO27799-11.2User Authentication for Clinicians0
ISO27799-11.3Remote Access to Clinical Systems0
ISO27799-12Unique user identification and authentication69
ISO27799-12.1Cryptography for Health Information1
ISO27799-13Automatic logoff and session management0
ISO27799-13.1Communications Security and Health Interfaces1
ISO27799-14Audit controls and monitoring0
ISO27799-14.1Secure Development of Clinical Applications0
ISO27799-15Integrity controls for ePHI0
ISO27799-15.1Supplier Relationships for Health IT1
ISO27799-16Transmission security and encryption112
ISO27799-16.1Incident Management for Health Data Breach0
ISO27799-17Facility access controls98
ISO27799-17.1Continuity of Clinical Operations0
ISO27799-18Workstation security and use policies0
ISO27799-18.1Compliance with Health Sector Regulations0
ISO27799-19Device and media controls0
ISO27799-20Disposal and re-use procedures0
ISO27799-21Security and privacy policies0
ISO27799-22Documentation and record retention0
ISO27799-23Compliance evaluation and review0
ISO27799-24Incident reporting procedures0
ISO27799-6.1Health Information Security Policy0
ISO27799-6.2Health Information Governance Committee0
ISO27799-7.1Asset Inventory for Health Records0
ISO27799-7.2Classification of Health Information0
ISO27799-8.1Workforce Security in Healthcare0
ISO27799-8.2Health Information Awareness Training0
ISO27799-9.1Physical Security in Healthcare Facilities0
ISO27799-9.2Equipment Security and Medical Devices0
55 Organizational controls0
5.15.1 Policies for information security0
5.115.11 Return of assets0
5.125.12 Classification of information0
5.135.13 Labelling of information0
5.145.14 Information transfer0
5.155.15 Access control0
5.165.16 Identity management0
5.175.17 Authentication information0
5.185.18 Access rights0
5.195.19 Information security in supplier relationships0
5.25.2 Information security roles and responsibilities0
5.215.21 Managing information security in the ICT supply chain0
5.235.23 Information security for use of cloud services0
5.245.24 Information security incident management planning and preparation0
5.255.25 Assessment and decision on information security events0
5.285.28 Collection of evidence0
5.35.3 Segregation of duties0
5.305.30 ICT readiness for business continuity0
5.345.34 Privacy and protection of PII0
5.355.35 Independent review of information security0
5.365.36 Conformance with policies, rules and standards for information security0
5.385.38 HLT: Information security requirements analysis and specification0
5.395.39 HLT: Uniquely identifying subjects of care0
5.405.40 HLT: Validation of displayed and printed data0
5.415.41 HLT: Publicly available health information0
5.425.42 HLT: Emergency communication0
5.435.43 HLT: External incident reporting0
5.65.6 Contact with special interest groups0
5.75.7 Threat intelligence0
5.85.8 Information security in project management0
5.95.9 Inventory of information and other associated assets0
66 People controls0
6.16.1 Screening0
6.26.2 Terms and conditions of employment0
6.36.3 Information security awareness, education and training0
6.46.4 Disciplinary process0
6.56.5 Responsibilities after termination or change of employment0
6.66.6 Confidentiality or non-disclosure agreements0
6.76.7 Remote working0
6.86.8 Information security event reporting0
6.96.9 HLT: Management training0
77 Physical controls0
7.17.1 Physical security perimeters0
7.107.10 Storage media0
7.117.11 Supporting utilities0
7.127.12 Cabling security0
7.137.13 Equipment maintenance0
7.147.14 Secure disposal or re-use of equipment0
7.27.2 Physical entry0
7.77.7 Clear desk and clear screen0
7.87.8 Equipment siting and protection0
7.97.9 Security of assets off-premises0
88 Technological controls0
8.18.1 User endpoint devices0
8.108.10 Information deletion0
8.118.11 Data masking0
8.138.13 Information backup0
8.158.15 Logging0
8.188.18 Use of privileged utility programs0
8.198.19 Installation of software on operational systems0
8.28.2 Privileged access rights0
8.218.21 Security of network services0
8.228.22 Segregation of networks0
8.238.23 Web filtering0
8.248.24 Use of cryptography0
8.268.26 Application security requirements0
8.298.29 Security testing in development and acceptance0
8.318.31 Separation of development, test and production environments0
8.328.32 Change management0
8.338.33 Test information0
8.358.35 HLT: Zero trust principles0
8.58.5 Secure authentication0
8.68.6 Capacity management0
8.78.7 Protection against malware0
8.88.8 Management of technical vulnerabilities0
8.98.9 Configuration management0
ANNEXAAnnex A (informative): the reference table of controls for health0
ANNEXBAnnex B (informative): correspondence with ISO 27799:20160
ANNEXCAnnex C (informative): information security in health organizations0
ANNEXDAnnex D (informative): example security and privacy requirements for health information systems0
FRONTClauses 1 to 4: scope, references, terms and how the controls are selected and applied0
STANDARDISO 27799:2025: the standard, its scope and what is held0
STATUSEdition status: ISO 27799:2025 is current; the held text is the DIS0

Tell me when ISO 27799:2025 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • critical service register
  • BIA outputs
  • service dependency map
  • critical service review
  • Regulatory register
  • Mapping to ISO 27799
  • Decision register
  • Governance objectives
  • Conformance report
  • Culture survey

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO 27799:2025, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition