ISO27799-01 | ePHI access controls and authorization | 122 |
ISO27799-02 | ePHI encryption at rest and in transit | 112 |
ISO27799-03 | Minimum necessary standard enforcement | 89 |
ISO27799-04 | Patient data de-identification procedures | 89 |
ISO27799-05 | Audit trail for ePHI access | 121 |
ISO27799-06 | Security management process and risk analysis | 123 |
ISO27799-07 | Workforce security and clearance procedures | 12 |
ISO27799-08 | Information access management | 98 |
ISO27799-09 | Security awareness and training program | 23 |
ISO27799-10 | Contingency planning for ePHI | 0 |
ISO27799-10.1 | Operational Procedures for Clinical Systems | 0 |
ISO27799-10.2 | Backup of Health Records | 0 |
ISO27799-10.3 | Audit Logging in Clinical Systems | 0 |
ISO27799-10.4 | Anti-malware on Clinical Endpoints | 0 |
ISO27799-11 | Business associate management | 0 |
ISO27799-11.1 | Access Control to Health Records | 1 |
ISO27799-11.2 | User Authentication for Clinicians | 0 |
ISO27799-11.3 | Remote Access to Clinical Systems | 0 |
ISO27799-12 | Unique user identification and authentication | 69 |
ISO27799-12.1 | Cryptography for Health Information | 1 |
ISO27799-13 | Automatic logoff and session management | 0 |
ISO27799-13.1 | Communications Security and Health Interfaces | 1 |
ISO27799-14 | Audit controls and monitoring | 0 |
ISO27799-14.1 | Secure Development of Clinical Applications | 0 |
ISO27799-15 | Integrity controls for ePHI | 0 |
ISO27799-15.1 | Supplier Relationships for Health IT | 1 |
ISO27799-16 | Transmission security and encryption | 112 |
ISO27799-16.1 | Incident Management for Health Data Breach | 0 |
ISO27799-17 | Facility access controls | 98 |
ISO27799-17.1 | Continuity of Clinical Operations | 0 |
ISO27799-18 | Workstation security and use policies | 0 |
ISO27799-18.1 | Compliance with Health Sector Regulations | 0 |
ISO27799-19 | Device and media controls | 0 |
ISO27799-20 | Disposal and re-use procedures | 0 |
ISO27799-21 | Security and privacy policies | 0 |
ISO27799-22 | Documentation and record retention | 0 |
ISO27799-23 | Compliance evaluation and review | 0 |
ISO27799-24 | Incident reporting procedures | 0 |
ISO27799-6.1 | Health Information Security Policy | 0 |
ISO27799-6.2 | Health Information Governance Committee | 0 |
ISO27799-7.1 | Asset Inventory for Health Records | 0 |
ISO27799-7.2 | Classification of Health Information | 0 |
ISO27799-8.1 | Workforce Security in Healthcare | 0 |
ISO27799-8.2 | Health Information Awareness Training | 0 |
ISO27799-9.1 | Physical Security in Healthcare Facilities | 0 |
ISO27799-9.2 | Equipment Security and Medical Devices | 0 |
5 | 5 Organizational controls | 0 |
5.1 | 5.1 Policies for information security | 0 |
5.11 | 5.11 Return of assets | 0 |
5.12 | 5.12 Classification of information | 0 |
5.13 | 5.13 Labelling of information | 0 |
5.14 | 5.14 Information transfer | 0 |
5.15 | 5.15 Access control | 0 |
5.16 | 5.16 Identity management | 0 |
5.17 | 5.17 Authentication information | 0 |
5.18 | 5.18 Access rights | 0 |
5.19 | 5.19 Information security in supplier relationships | 0 |
5.2 | 5.2 Information security roles and responsibilities | 0 |
5.21 | 5.21 Managing information security in the ICT supply chain | 0 |
5.23 | 5.23 Information security for use of cloud services | 0 |
5.24 | 5.24 Information security incident management planning and preparation | 0 |
5.25 | 5.25 Assessment and decision on information security events | 0 |
5.28 | 5.28 Collection of evidence | 0 |
5.3 | 5.3 Segregation of duties | 0 |
5.30 | 5.30 ICT readiness for business continuity | 0 |
5.34 | 5.34 Privacy and protection of PII | 0 |
5.35 | 5.35 Independent review of information security | 0 |
5.36 | 5.36 Conformance with policies, rules and standards for information security | 0 |
5.38 | 5.38 HLT: Information security requirements analysis and specification | 0 |
5.39 | 5.39 HLT: Uniquely identifying subjects of care | 0 |
5.40 | 5.40 HLT: Validation of displayed and printed data | 0 |
5.41 | 5.41 HLT: Publicly available health information | 0 |
5.42 | 5.42 HLT: Emergency communication | 0 |
5.43 | 5.43 HLT: External incident reporting | 0 |
5.6 | 5.6 Contact with special interest groups | 0 |
5.7 | 5.7 Threat intelligence | 0 |
5.8 | 5.8 Information security in project management | 0 |
5.9 | 5.9 Inventory of information and other associated assets | 0 |
6 | 6 People controls | 0 |
6.1 | 6.1 Screening | 0 |
6.2 | 6.2 Terms and conditions of employment | 0 |
6.3 | 6.3 Information security awareness, education and training | 0 |
6.4 | 6.4 Disciplinary process | 0 |
6.5 | 6.5 Responsibilities after termination or change of employment | 0 |
6.6 | 6.6 Confidentiality or non-disclosure agreements | 0 |
6.7 | 6.7 Remote working | 0 |
6.8 | 6.8 Information security event reporting | 0 |
6.9 | 6.9 HLT: Management training | 0 |
7 | 7 Physical controls | 0 |
7.1 | 7.1 Physical security perimeters | 0 |
7.10 | 7.10 Storage media | 0 |
7.11 | 7.11 Supporting utilities | 0 |
7.12 | 7.12 Cabling security | 0 |
7.13 | 7.13 Equipment maintenance | 0 |
7.14 | 7.14 Secure disposal or re-use of equipment | 0 |
7.2 | 7.2 Physical entry | 0 |
7.7 | 7.7 Clear desk and clear screen | 0 |
7.8 | 7.8 Equipment siting and protection | 0 |
7.9 | 7.9 Security of assets off-premises | 0 |
8 | 8 Technological controls | 0 |
8.1 | 8.1 User endpoint devices | 0 |
8.10 | 8.10 Information deletion | 0 |
8.11 | 8.11 Data masking | 0 |
8.13 | 8.13 Information backup | 0 |
8.15 | 8.15 Logging | 0 |
8.18 | 8.18 Use of privileged utility programs | 0 |
8.19 | 8.19 Installation of software on operational systems | 0 |
8.2 | 8.2 Privileged access rights | 0 |
8.21 | 8.21 Security of network services | 0 |
8.22 | 8.22 Segregation of networks | 0 |
8.23 | 8.23 Web filtering | 0 |
8.24 | 8.24 Use of cryptography | 0 |
8.26 | 8.26 Application security requirements | 0 |
8.29 | 8.29 Security testing in development and acceptance | 0 |
8.31 | 8.31 Separation of development, test and production environments | 0 |
8.32 | 8.32 Change management | 0 |
8.33 | 8.33 Test information | 0 |
8.35 | 8.35 HLT: Zero trust principles | 0 |
8.5 | 8.5 Secure authentication | 0 |
8.6 | 8.6 Capacity management | 0 |
8.7 | 8.7 Protection against malware | 0 |
8.8 | 8.8 Management of technical vulnerabilities | 0 |
8.9 | 8.9 Configuration management | 0 |
ANNEXA | Annex A (informative): the reference table of controls for health | 0 |
ANNEXB | Annex B (informative): correspondence with ISO 27799:2016 | 0 |
ANNEXC | Annex C (informative): information security in health organizations | 0 |
ANNEXD | Annex D (informative): example security and privacy requirements for health information systems | 0 |
FRONT | Clauses 1 to 4: scope, references, terms and how the controls are selected and applied | 0 |
STANDARD | ISO 27799:2025: the standard, its scope and what is held | 0 |
STATUS | Edition status: ISO 27799:2025 is current; the held text is the DIS | 0 |