Skip to content

Evidence request lists

ISO 27799

Evidence request list. 46 controls, 46 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Access Control

ISO27799-11.1
Access Control to Health Records

Role-based access tied to clinical role with need-to-know enforcement.

Artefacts an auditor will ask for
  • Role catalogue
  • Access reviews
  • Need-to-know enforcement evidence
  • Joiner-mover-leaver records
Where this commonly fails
  • Excess access
  • Mover never reviewed
  • Leaver accounts active
ISO27799-11.2
User Authentication for Clinicians

Strong authentication for clinical users including MFA and SSO.

Artefacts an auditor will ask for
  • MFA coverage
  • SSO integration
  • Smartcard policy
  • Shared workstation procedures
Where this commonly fails
  • MFA exempted for clinicians
  • Shared accounts
  • Smartcards loaned
ISO27799-11.3
Remote Access to Clinical Systems

Secure remote access for telemedicine, on-call, and home working.

Artefacts an auditor will ask for
  • VPN configuration
  • Telemedicine platform attestation
  • Home working policy
  • Device posture checks
Where this commonly fails
  • Personal devices
  • No posture check
  • Telemedicine on consumer apps

Acquisition

ISO27799-14.1
Secure Development of Clinical Applications

Apply secure SDLC to in-house clinical applications and integration code.

Artefacts an auditor will ask for
  • Coding standards
  • Code review records
  • Static analysis output
  • Penetration tests
Where this commonly fails
  • No reviews
  • Static analysis off
  • Pen tests skipped

Asset Management

ISO27799-7.1
Asset Inventory for Health Records

Inventory EHR systems, PACS, lab systems, medical devices, and paper records.

Artefacts an auditor will ask for
  • Health system register
  • Device inventory
  • Paper records map
  • Owners assigned
Where this commonly fails
  • Medical devices uncounted
  • Paper excluded
  • Owners outdated
ISO27799-7.2
Classification of Health Information

Classify health data according to sensitivity including mental health and genetic categories.

Artefacts an auditor will ask for
  • Classification scheme with health categories
  • Labelling examples
  • Genetic data flag
  • Handling rules
Where this commonly fails
  • No special category flag
  • Genetic treated as general
  • Labels missing

Communications

ISO27799-13.1
Communications Security and Health Interfaces

Secure interfaces between EHR, lab, imaging, and external partners.

Artefacts an auditor will ask for
  • Interface register
  • DICOM/HL7 security review
  • Partner connection list
  • Firewall ACLs
Where this commonly fails
  • Unknown interfaces
  • DICOM open
  • Partners unreviewed

Compliance

ISO27799-18.1
Compliance with Health Sector Regulations

Meet sector regulations such as HIPAA, GDPR Article 9, national health acts.

Artefacts an auditor will ask for
  • Regulatory register
  • Mapping to ISO 27799
  • Audit findings
  • Notification logs
Where this commonly fails
  • Register incomplete
  • Mapping outdated
  • Findings open

Continuity

ISO27799-17.1
Continuity of Clinical Operations

Continuity arrangements maintain patient care during IT disruption.

Artefacts an auditor will ask for
  • Clinical BCP
  • Downtime forms
  • Paper fallback procedure
  • Drill records
Where this commonly fails
  • No paper fallback
  • Drill skipped
  • Pharmacy not covered

Cryptography

ISO27799-12.1
Cryptography for Health Information

Use cryptography to protect health data at rest, in transit, and in messaging.

Artefacts an auditor will ask for
  • Encryption inventory
  • Key management procedure
  • TLS configuration
  • HL7/FHIR message encryption
Where this commonly fails
  • HL7 in clear
  • Keys in code
  • TLS 1.0 still enabled

Governance

ISO27799-6.1
Health Information Security Policy

Maintain a health-specific information security policy aligned with clinical and regulatory needs.

Artefacts an auditor will ask for
  • Approved health ISMS policy
  • Clinical input record
  • Regulatory mapping
  • Review schedule
Where this commonly fails
  • Generic policy reused
  • No clinician input
  • Mapping stale
ISO27799-6.2
Health Information Governance Committee

Establish a committee with clinical, IT, privacy, and risk representation.

Artefacts an auditor will ask for
  • Committee charter
  • Meeting minutes
  • Membership list
  • Decision log
Where this commonly fails
  • No clinician seat
  • Minutes missing
  • Decisions undocumented

ISO 27799: Administrative Safeguards

ISO27799-06
Security management process and risk analysis

Security management process and risk analysis. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.

Artefacts an auditor will ask for
  • Workforce clearance procedure
  • Security training records
  • Business associate agreement
  • Contingency plan
Where this commonly fails
  • Workforce clearance lapses
  • Training not role-tailored
  • BAAs not refreshed
ISO27799-07
Workforce security and clearance procedures

Workforce security and clearance procedures. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.

Artefacts an auditor will ask for
  • Workforce clearance procedure
  • Security training records
  • Business associate agreement
  • Contingency plan
Where this commonly fails
  • Workforce clearance lapses
  • Training not role-tailored
  • BAAs not refreshed
ISO27799-08
Information access management

Information access management. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.

Artefacts an auditor will ask for
  • Workforce clearance procedure
  • Security training records
  • Business associate agreement
  • Contingency plan
Where this commonly fails
  • Workforce clearance lapses
  • Training not role-tailored
  • BAAs not refreshed
ISO27799-09
Security awareness and training program

Security awareness and training program. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.

Artefacts an auditor will ask for
  • Workforce clearance procedure
  • Security training records
  • Business associate agreement
  • Contingency plan
Where this commonly fails
  • Workforce clearance lapses
  • Training not role-tailored
  • BAAs not refreshed
ISO27799-10
Contingency planning for ePHI

Contingency planning for ePHI. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.

Artefacts an auditor will ask for
  • ePHI access control policy
  • De-identification procedure
  • Audit trail report
  • Minimum necessary review
Where this commonly fails
  • Audit trails not reviewed
  • De-identification re-identification risk not assessed
  • Minimum necessary not enforced in EHR
ISO27799-11
Business associate management

Business associate management. Control from ISO 27799 framework, domain: ISO 27799: Administrative Safeguards.

Artefacts an auditor will ask for
  • Workforce clearance procedure
  • Security training records
  • Business associate agreement
  • Contingency plan
Where this commonly fails
  • Workforce clearance lapses
  • Training not role-tailored
  • BAAs not refreshed

ISO 27799: Organizational Requirements

ISO27799-21
Security and privacy policies

Security and privacy policies. Control from ISO 27799 framework, domain: ISO 27799: Organizational Requirements.

Artefacts an auditor will ask for
  • Security and privacy policy set
  • Documentation retention schedule
  • Compliance review report
  • Incident report template
Where this commonly fails
  • Retention schedule not enforced
  • Policies not signed by clinicians
  • Incident reports under-filed
ISO27799-22
Documentation and record retention

Documentation and record retention. Control from ISO 27799 framework, domain: ISO 27799: Organizational Requirements.

Artefacts an auditor will ask for
  • Security and privacy policy set
  • Documentation retention schedule
  • Compliance review report
  • Incident report template
Where this commonly fails
  • Retention schedule not enforced
  • Policies not signed by clinicians
  • Incident reports under-filed
ISO27799-23
Compliance evaluation and review

Compliance evaluation and review. Control from ISO 27799 framework, domain: ISO 27799: Organizational Requirements.

Artefacts an auditor will ask for
  • Security and privacy policy set
  • Documentation retention schedule
  • Compliance review report
  • Incident report template
Where this commonly fails
  • Retention schedule not enforced
  • Policies not signed by clinicians
  • Incident reports under-filed
ISO27799-24
Incident reporting procedures

Incident reporting procedures. Control from ISO 27799 framework, domain: ISO 27799: Organizational Requirements.

Artefacts an auditor will ask for
  • Security and privacy policy set
  • Documentation retention schedule
  • Compliance review report
  • Incident report template
Where this commonly fails
  • Retention schedule not enforced
  • Policies not signed by clinicians
  • Incident reports under-filed

ISO 27799: Patient Data Protection

ISO27799-01
ePHI access controls and authorization

ePHI access controls and authorization. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.

Artefacts an auditor will ask for
  • ePHI access control policy
  • De-identification procedure
  • Audit trail report
  • Minimum necessary review
Where this commonly fails
  • Audit trails not reviewed
  • De-identification re-identification risk not assessed
  • Minimum necessary not enforced in EHR
ISO27799-02
ePHI encryption at rest and in transit

ePHI encryption at rest and in transit. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.

Artefacts an auditor will ask for
  • ePHI access control policy
  • De-identification procedure
  • Audit trail report
  • Minimum necessary review
Where this commonly fails
  • Audit trails not reviewed
  • De-identification re-identification risk not assessed
  • Minimum necessary not enforced in EHR
ISO27799-03
Minimum necessary standard enforcement

Minimum necessary standard enforcement. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.

Artefacts an auditor will ask for
  • ePHI access control policy
  • De-identification procedure
  • Audit trail report
  • Minimum necessary review
Where this commonly fails
  • Audit trails not reviewed
  • De-identification re-identification risk not assessed
  • Minimum necessary not enforced in EHR
ISO27799-04
Patient data de-identification procedures

Patient data de-identification procedures. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.

Artefacts an auditor will ask for
  • ePHI access control policy
  • De-identification procedure
  • Audit trail report
  • Minimum necessary review
Where this commonly fails
  • Audit trails not reviewed
  • De-identification re-identification risk not assessed
  • Minimum necessary not enforced in EHR
ISO27799-05
Audit trail for ePHI access

Audit trail for ePHI access. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.

Artefacts an auditor will ask for
  • ePHI access control policy
  • De-identification procedure
  • Audit trail report
  • Minimum necessary review
Where this commonly fails
  • Audit trails not reviewed
  • De-identification re-identification risk not assessed
  • Minimum necessary not enforced in EHR

ISO 27799: Physical Safeguards

ISO27799-17
Facility access controls

Facility access controls. Control from ISO 27799 framework, domain: ISO 27799: Physical Safeguards.

Artefacts an auditor will ask for
  • Facility access procedure
  • Workstation use policy
  • Device inventory
  • Disposal certificate
Where this commonly fails
  • Tailgating in clinical areas
  • Workstations unattended logged in
  • Device disposal not certified
ISO27799-18
Workstation security and use policies

Workstation security and use policies. Control from ISO 27799 framework, domain: ISO 27799: Physical Safeguards.

Artefacts an auditor will ask for
  • Facility access procedure
  • Workstation use policy
  • Device inventory
  • Disposal certificate
Where this commonly fails
  • Tailgating in clinical areas
  • Workstations unattended logged in
  • Device disposal not certified
ISO27799-19
Device and media controls

Device and media controls. Control from ISO 27799 framework, domain: ISO 27799: Physical Safeguards.

Artefacts an auditor will ask for
  • Facility access procedure
  • Workstation use policy
  • Device inventory
  • Disposal certificate
Where this commonly fails
  • Tailgating in clinical areas
  • Workstations unattended logged in
  • Device disposal not certified
ISO27799-20
Disposal and re-use procedures

Disposal and re-use procedures. Control from ISO 27799 framework, domain: ISO 27799: Physical Safeguards.

Artefacts an auditor will ask for
  • Facility access procedure
  • Workstation use policy
  • Device inventory
  • Disposal certificate
Where this commonly fails
  • Tailgating in clinical areas
  • Workstations unattended logged in
  • Device disposal not certified

ISO 27799: Technical Safeguards

ISO27799-12
Unique user identification and authentication

Unique user identification and authentication. Control from ISO 27799 framework, domain: ISO 27799: Technical Safeguards.

Artefacts an auditor will ask for
  • Unique user ID standard
  • Session timeout configuration
  • Integrity hash logs
  • Transmission encryption baseline
Where this commonly fails
  • Shared accounts persist in clinical systems
  • Session timeouts too long
  • Legacy HL7 unencrypted
ISO27799-13
Automatic logoff and session management

Automatic logoff and session management. Control from ISO 27799 framework, domain: ISO 27799: Technical Safeguards.

Artefacts an auditor will ask for
  • Unique user ID standard
  • Session timeout configuration
  • Integrity hash logs
  • Transmission encryption baseline
Where this commonly fails
  • Shared accounts persist in clinical systems
  • Session timeouts too long
  • Legacy HL7 unencrypted
ISO27799-14
Audit controls and monitoring

Audit controls and monitoring. Control from ISO 27799 framework, domain: ISO 27799: Technical Safeguards.

Artefacts an auditor will ask for
  • Unique user ID standard
  • Session timeout configuration
  • Integrity hash logs
  • Transmission encryption baseline
Where this commonly fails
  • Shared accounts persist in clinical systems
  • Session timeouts too long
  • Legacy HL7 unencrypted
ISO27799-15
Integrity controls for ePHI

Integrity controls for ePHI. Control from ISO 27799 framework, domain: ISO 27799: Technical Safeguards.

Artefacts an auditor will ask for
  • ePHI access control policy
  • De-identification procedure
  • Audit trail report
  • Minimum necessary review
Where this commonly fails
  • Audit trails not reviewed
  • De-identification re-identification risk not assessed
  • Minimum necessary not enforced in EHR
ISO27799-16
Transmission security and encryption

Transmission security and encryption. Control from ISO 27799 framework, domain: ISO 27799: Technical Safeguards.

Artefacts an auditor will ask for
  • Unique user ID standard
  • Session timeout configuration
  • Integrity hash logs
  • Transmission encryption baseline
Where this commonly fails
  • Shared accounts persist in clinical systems
  • Session timeouts too long
  • Legacy HL7 unencrypted

Incident

ISO27799-16.1
Incident Management for Health Data Breach

Incident response including patient notification and regulator timing.

Artefacts an auditor will ask for
  • IR plan with health scenarios
  • Patient notification templates
  • Regulator notification log
  • Tabletop results
Where this commonly fails
  • No patient template
  • Regulator timing missed
  • No clinical scenario

Operations

ISO27799-10.1
Operational Procedures for Clinical Systems

Documented operations for EHR, ePrescribing, and lab interface systems.

Artefacts an auditor will ask for
  • Runbooks
  • Downtime procedures
  • Manual workarounds
  • Operator handover logs
Where this commonly fails
  • No downtime plan
  • Tribal knowledge
  • Handovers verbal
ISO27799-10.2
Backup of Health Records

Backup health records with frequency aligned to clinical risk and tested restores.

Artefacts an auditor will ask for
  • Backup schedule
  • Restore test logs
  • Offsite evidence
  • RPO/RTO statements
Where this commonly fails
  • Restore never tested
  • No offsite
  • RPO not defined
ISO27799-10.3
Audit Logging in Clinical Systems

Log access to patient records including read access and break-glass events.

Artefacts an auditor will ask for
  • Read access logs
  • Break-glass alerts
  • Log review evidence
  • Patient complaint follow-up
Where this commonly fails
  • Read access not logged
  • Break-glass unreviewed
  • Patient complaints unmatched
ISO27799-10.4
Anti-malware on Clinical Endpoints

Anti-malware on clinical endpoints with safe update windows.

Artefacts an auditor will ask for
  • AV coverage report
  • Definition currency
  • Quarantine logs
  • Update window policy
Where this commonly fails
  • AV disabled on shared PCs
  • Updates skipped during shift
  • No quarantine review

People

ISO27799-8.1
Workforce Security in Healthcare

Screening, training, and confidentiality undertakings for clinical and administrative staff.

Artefacts an auditor will ask for
  • Screening records
  • Confidentiality undertakings
  • Training completion
  • Locum policy
Where this commonly fails
  • Locums unchecked
  • Training stale
  • Undertakings missing
ISO27799-8.2
Health Information Awareness Training

Train workforce on patient privacy, consent, and breach reporting.

Artefacts an auditor will ask for
  • Training curriculum
  • Completion records
  • Phishing test results
  • Refresher schedule
Where this commonly fails
  • Clinical staff exempted
  • No phishing tests
  • Refresher overdue

Physical

ISO27799-9.1
Physical Security in Healthcare Facilities

Secure clinical areas, server rooms, records storage, and pharmacy.

Artefacts an auditor will ask for
  • Access control logs
  • CCTV evidence
  • Records room audit
  • Pharmacy security
Where this commonly fails
  • Records room unlocked
  • CCTV gaps
  • Pharmacy shared key
ISO27799-9.2
Equipment Security and Medical Devices

Secure workstations, mobile devices, and connected medical devices on the network.

Artefacts an auditor will ask for
  • Device inventory
  • Network segmentation evidence
  • Disposal certificates
  • MDS2 forms
Where this commonly fails
  • Devices on flat LAN
  • No MDS2
  • Disposal informal

Supplier

ISO27799-15.1
Supplier Relationships for Health IT

Manage suppliers of EHR, medical devices, cloud, and outsourced clinical services.

Artefacts an auditor will ask for
  • Supplier register
  • BAA-equivalent clauses
  • Vendor security questionnaires
  • Audit results
Where this commonly fails
  • Cloud vendor unreviewed
  • Device vendor no clauses
  • Questionnaire stale
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27799 framework page.