ISO 27799
Evidence request list. 46 controls, 46 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Access Control
Role-based access tied to clinical role with need-to-know enforcement.
- Role catalogue
- Access reviews
- Need-to-know enforcement evidence
- Joiner-mover-leaver records
- Excess access
- Mover never reviewed
- Leaver accounts active
Strong authentication for clinical users including MFA and SSO.
- MFA coverage
- SSO integration
- Smartcard policy
- Shared workstation procedures
- MFA exempted for clinicians
- Shared accounts
- Smartcards loaned
Secure remote access for telemedicine, on-call, and home working.
- VPN configuration
- Telemedicine platform attestation
- Home working policy
- Device posture checks
- Personal devices
- No posture check
- Telemedicine on consumer apps
Acquisition
Apply secure SDLC to in-house clinical applications and integration code.
- Coding standards
- Code review records
- Static analysis output
- Penetration tests
- No reviews
- Static analysis off
- Pen tests skipped
Asset Management
Inventory EHR systems, PACS, lab systems, medical devices, and paper records.
- Health system register
- Device inventory
- Paper records map
- Owners assigned
- Medical devices uncounted
- Paper excluded
- Owners outdated
Classify health data according to sensitivity including mental health and genetic categories.
- Classification scheme with health categories
- Labelling examples
- Genetic data flag
- Handling rules
- No special category flag
- Genetic treated as general
- Labels missing
Communications
Secure interfaces between EHR, lab, imaging, and external partners.
- Interface register
- DICOM/HL7 security review
- Partner connection list
- Firewall ACLs
- Unknown interfaces
- DICOM open
- Partners unreviewed
Compliance
Meet sector regulations such as HIPAA, GDPR Article 9, national health acts.
- Regulatory register
- Mapping to ISO 27799
- Audit findings
- Notification logs
- Register incomplete
- Mapping outdated
- Findings open
Continuity
Continuity arrangements maintain patient care during IT disruption.
- Clinical BCP
- Downtime forms
- Paper fallback procedure
- Drill records
- No paper fallback
- Drill skipped
- Pharmacy not covered
Cryptography
Use cryptography to protect health data at rest, in transit, and in messaging.
- Encryption inventory
- Key management procedure
- TLS configuration
- HL7/FHIR message encryption
- HL7 in clear
- Keys in code
- TLS 1.0 still enabled
Governance
Maintain a health-specific information security policy aligned with clinical and regulatory needs.
- Approved health ISMS policy
- Clinical input record
- Regulatory mapping
- Review schedule
- Generic policy reused
- No clinician input
- Mapping stale
Establish a committee with clinical, IT, privacy, and risk representation.
- Committee charter
- Meeting minutes
- Membership list
- Decision log
- No clinician seat
- Minutes missing
- Decisions undocumented
ISO 27799: Administrative Safeguards
Security management process and risk analysis. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.
- Workforce clearance procedure
- Security training records
- Business associate agreement
- Contingency plan
- Workforce clearance lapses
- Training not role-tailored
- BAAs not refreshed
Workforce security and clearance procedures. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.
- Workforce clearance procedure
- Security training records
- Business associate agreement
- Contingency plan
- Workforce clearance lapses
- Training not role-tailored
- BAAs not refreshed
Information access management. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.
- Workforce clearance procedure
- Security training records
- Business associate agreement
- Contingency plan
- Workforce clearance lapses
- Training not role-tailored
- BAAs not refreshed
Security awareness and training program. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.
- Workforce clearance procedure
- Security training records
- Business associate agreement
- Contingency plan
- Workforce clearance lapses
- Training not role-tailored
- BAAs not refreshed
Contingency planning for ePHI. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.
- ePHI access control policy
- De-identification procedure
- Audit trail report
- Minimum necessary review
- Audit trails not reviewed
- De-identification re-identification risk not assessed
- Minimum necessary not enforced in EHR
Business associate management. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.
- Workforce clearance procedure
- Security training records
- Business associate agreement
- Contingency plan
- Workforce clearance lapses
- Training not role-tailored
- BAAs not refreshed
ISO 27799: Organizational Requirements
Security and privacy policies. Control from ISO 27799 framework, domain: ISO 27799: Organizational Requirements.
- Security and privacy policy set
- Documentation retention schedule
- Compliance review report
- Incident report template
- Retention schedule not enforced
- Policies not signed by clinicians
- Incident reports under-filed
Documentation and record retention. Control from ISO 27799 framework, domain: ISO 27799: Organizational Requirements.
- Security and privacy policy set
- Documentation retention schedule
- Compliance review report
- Incident report template
- Retention schedule not enforced
- Policies not signed by clinicians
- Incident reports under-filed
Compliance evaluation and review. Control from ISO 27799 framework, domain: ISO 27799: Organizational Requirements.
- Security and privacy policy set
- Documentation retention schedule
- Compliance review report
- Incident report template
- Retention schedule not enforced
- Policies not signed by clinicians
- Incident reports under-filed
Incident reporting procedures. Control from ISO 27799 framework, domain: ISO 27799: Organizational Requirements.
- Security and privacy policy set
- Documentation retention schedule
- Compliance review report
- Incident report template
- Retention schedule not enforced
- Policies not signed by clinicians
- Incident reports under-filed
ISO 27799: Patient Data Protection
ePHI access controls and authorization. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.
- ePHI access control policy
- De-identification procedure
- Audit trail report
- Minimum necessary review
- Audit trails not reviewed
- De-identification re-identification risk not assessed
- Minimum necessary not enforced in EHR
ePHI encryption at rest and in transit. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.
- ePHI access control policy
- De-identification procedure
- Audit trail report
- Minimum necessary review
- Audit trails not reviewed
- De-identification re-identification risk not assessed
- Minimum necessary not enforced in EHR
Minimum necessary standard enforcement. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.
- ePHI access control policy
- De-identification procedure
- Audit trail report
- Minimum necessary review
- Audit trails not reviewed
- De-identification re-identification risk not assessed
- Minimum necessary not enforced in EHR
Patient data de-identification procedures. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.
- ePHI access control policy
- De-identification procedure
- Audit trail report
- Minimum necessary review
- Audit trails not reviewed
- De-identification re-identification risk not assessed
- Minimum necessary not enforced in EHR
Audit trail for ePHI access. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.
- ePHI access control policy
- De-identification procedure
- Audit trail report
- Minimum necessary review
- Audit trails not reviewed
- De-identification re-identification risk not assessed
- Minimum necessary not enforced in EHR
ISO 27799: Physical Safeguards
Facility access controls. Control from ISO 27799 framework, domain: ISO 27799: Physical Safeguards.
- Facility access procedure
- Workstation use policy
- Device inventory
- Disposal certificate
- Tailgating in clinical areas
- Workstations unattended logged in
- Device disposal not certified
Workstation security and use policies. Control from ISO 27799 framework, domain: ISO 27799: Physical Safeguards.
- Facility access procedure
- Workstation use policy
- Device inventory
- Disposal certificate
- Tailgating in clinical areas
- Workstations unattended logged in
- Device disposal not certified
Device and media controls. Control from ISO 27799 framework, domain: ISO 27799: Physical Safeguards.
- Facility access procedure
- Workstation use policy
- Device inventory
- Disposal certificate
- Tailgating in clinical areas
- Workstations unattended logged in
- Device disposal not certified
Disposal and re-use procedures. Control from ISO 27799 framework, domain: ISO 27799: Physical Safeguards.
- Facility access procedure
- Workstation use policy
- Device inventory
- Disposal certificate
- Tailgating in clinical areas
- Workstations unattended logged in
- Device disposal not certified
ISO 27799: Technical Safeguards
Unique user identification and authentication. Control from ISO 27799 framework, domain: ISO 27799: Technical Safeguards.
- Unique user ID standard
- Session timeout configuration
- Integrity hash logs
- Transmission encryption baseline
- Shared accounts persist in clinical systems
- Session timeouts too long
- Legacy HL7 unencrypted
Automatic logoff and session management. Control from ISO 27799 framework, domain: ISO 27799: Technical Safeguards.
- Unique user ID standard
- Session timeout configuration
- Integrity hash logs
- Transmission encryption baseline
- Shared accounts persist in clinical systems
- Session timeouts too long
- Legacy HL7 unencrypted
Audit controls and monitoring. Control from ISO 27799 framework, domain: ISO 27799: Technical Safeguards.
- Unique user ID standard
- Session timeout configuration
- Integrity hash logs
- Transmission encryption baseline
- Shared accounts persist in clinical systems
- Session timeouts too long
- Legacy HL7 unencrypted
Integrity controls for ePHI. Control from ISO 27799 framework, domain: ISO 27799: Technical Safeguards.
- ePHI access control policy
- De-identification procedure
- Audit trail report
- Minimum necessary review
- Audit trails not reviewed
- De-identification re-identification risk not assessed
- Minimum necessary not enforced in EHR
Transmission security and encryption. Control from ISO 27799 framework, domain: ISO 27799: Technical Safeguards.
- Unique user ID standard
- Session timeout configuration
- Integrity hash logs
- Transmission encryption baseline
- Shared accounts persist in clinical systems
- Session timeouts too long
- Legacy HL7 unencrypted
Incident
Incident response including patient notification and regulator timing.
- IR plan with health scenarios
- Patient notification templates
- Regulator notification log
- Tabletop results
- No patient template
- Regulator timing missed
- No clinical scenario
Operations
Documented operations for EHR, ePrescribing, and lab interface systems.
- Runbooks
- Downtime procedures
- Manual workarounds
- Operator handover logs
- No downtime plan
- Tribal knowledge
- Handovers verbal
Backup health records with frequency aligned to clinical risk and tested restores.
- Backup schedule
- Restore test logs
- Offsite evidence
- RPO/RTO statements
- Restore never tested
- No offsite
- RPO not defined
Log access to patient records including read access and break-glass events.
- Read access logs
- Break-glass alerts
- Log review evidence
- Patient complaint follow-up
- Read access not logged
- Break-glass unreviewed
- Patient complaints unmatched
Anti-malware on clinical endpoints with safe update windows.
- AV coverage report
- Definition currency
- Quarantine logs
- Update window policy
- AV disabled on shared PCs
- Updates skipped during shift
- No quarantine review
People
Screening, training, and confidentiality undertakings for clinical and administrative staff.
- Screening records
- Confidentiality undertakings
- Training completion
- Locum policy
- Locums unchecked
- Training stale
- Undertakings missing
Train workforce on patient privacy, consent, and breach reporting.
- Training curriculum
- Completion records
- Phishing test results
- Refresher schedule
- Clinical staff exempted
- No phishing tests
- Refresher overdue
Physical
Secure clinical areas, server rooms, records storage, and pharmacy.
- Access control logs
- CCTV evidence
- Records room audit
- Pharmacy security
- Records room unlocked
- CCTV gaps
- Pharmacy shared key
Secure workstations, mobile devices, and connected medical devices on the network.
- Device inventory
- Network segmentation evidence
- Disposal certificates
- MDS2 forms
- Devices on flat LAN
- No MDS2
- Disposal informal
Supplier
Manage suppliers of EHR, medical devices, cloud, and outsourced clinical services.
- Supplier register
- BAA-equivalent clauses
- Vendor security questionnaires
- Audit results
- Cloud vendor unreviewed
- Device vendor no clauses
- Questionnaire stale
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27799 framework page.