# ISO 27799:2016 Health Informatics — Information Security Management in Health

Framework id: `iso_27799`. Health Informatics. Publisher: ISO/IEC. Version: 2016. Region: Global. Mapping licence: CC BY-SA 4.0.
Source text: https://www.iso.org/standard/62777.html

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (48, average coverage 81%)
- 5.1 Health organisation information security policy: PL-01, PM-01, AC-01, AT-01, AU-01, CA-01, CM-01, CP-01, IA-01, IR-01, MA-01, MP-01, PE-01, PS-01, RA-01, SA-01, SC-01, SI-01, PT-01, SR-01 (88%)
- 5.2 Review of health information security policies: PL-01, PM-01, PM-06, CA-07 (82%)
- 5.3 Health data classification policy: RA-02, AC-16, MP-03, PT-02, PT-03 (78%)
- 6.1 Internal organisation for health information security: PM-01, PM-02, PM-10, PM-29, PS-01, PS-09 (82%)
- 6.2 Health information security roles and responsibilities: PM-02, PS-01, PS-02, PS-09, PL-01 (85%)
- 6.3 Mobile devices and teleworking in clinical contexts: AC-17, AC-19, AC-20, PE-17, SC-28, CM-07 (80%)
- 7.1 Before employment in health settings: PS-01, PS-02, PS-03, PS-06 (85%)
- 7.2 During employment in health settings: AT-01, AT-02, AT-03, AT-04, AT-06, PS-06, PS-07, PL-04, PM-13 (85%)
- 7.3 Termination and change of employment in health settings: PS-04, PS-05, AC-02, IA-04 (88%)
- 8.1 Health information asset inventory and ownership: CM-08, PM-05, CM-12, CM-13, RA-02 (85%)
- 8.2 Classification of health data: RA-02, AC-16, MP-03, PT-02, PT-03, PT-06, PT-07 (75%)
- 8.3 Acceptable use and return of health assets: PL-04, AC-20, MP-07, PS-04, PS-05 (88%)
- 9.1 Business requirements for health data access control: AC-01, AC-02, AC-03, AC-06, AC-24, AC-25 (88%)
- 9.2 Break-glass and emergency access procedures: AC-02, AC-14, CP-02, CP-10, AU-02, AU-06, AU-12 (72%)
- 9.3 User access management for clinical systems: AC-02, AC-05, AC-06, IA-04, IA-05, IA-02, IA-12, PS-03 (90%)
- 9.4 Clinical user responsibilities and shared workstations: AC-11, AC-12, IA-02, IA-05, IA-11, PL-04, PE-05 (82%)
- 9.5 System and application access for EHR and clinical systems: AC-03, AC-04, AC-06, AC-07, AC-08, AC-10, AC-17, SC-10, SC-23 (88%)
- 10.1 Cryptographic controls for PHI: SC-12, SC-13, SC-28, SC-08 (90%)
- 10.2 Key management for health data encryption: SC-12, SC-17 (90%)
- 11.1 Secure areas in clinical environments: PE-01, PE-02, PE-03, PE-04, PE-05, PE-06, PE-07, PE-08, PE-18 (88%)
- 11.2 Equipment security for medical devices and mobile clinical devices: PE-01, PE-14, PE-18, PE-23, AC-19, CM-08, MA-01, MA-02, MA-05 (78%)
- 12.1 Operational procedures for health IT systems: PL-02, SA-05, CM-01, CM-02, CM-06 (82%)
- 12.2 Protection from malware in clinical systems: SI-03, SI-04, SI-08, SC-44 (88%)
- 12.3 Backup and clinical data continuity: CP-09, CP-06, MP-04, MP-05, SC-28 (90%)
- 12.4 Clinical audit trails and logging: AU-01, AU-02, AU-03, AU-04, AU-05, AU-06, AU-07, AU-08, AU-09, AU-11, AU-12, AU-14 (88%)
- 12.5 Vulnerability management for clinical systems: RA-05, SI-02, SI-05, CM-03, CM-04 (82%)
- 13.1 Network security for health information exchange: SC-07, SC-08, SC-32, AC-04, CA-03, CA-09, SC-46 (82%)
- 13.2 Information transfer for health data sharing and referrals: SC-08, AC-04, AC-20, CA-03, MP-05, SC-12, SC-13 (78%)
- 14.1 Security requirements for health IT procurement: SA-04, SA-08, SA-09, SA-03, SR-01, SR-02, SR-03 (85%)
- 14.2 Security in EHR development and customisation: SA-03, SA-08, SA-10, SA-11, SA-15, SA-17, CM-04 (88%)
- 14.3 Test data and use of clinical data in testing: SA-11, SA-15, SI-19, PT-06, PT-07 (75%)
- 15.1 Health IT supplier management: SA-04, SA-09, SR-01, SR-02, SR-03, SR-05, SR-06 (82%)
- 15.2 Medical device supply chain and cloud services for health data: SA-09, SR-01, SR-03, SR-05, SR-06, SR-11, AC-20 (78%)
- 16.1 Health data breach response planning: IR-01, IR-02, IR-03, IR-04, IR-07, IR-08, PM-15 (85%)
- 16.2 Clinical safety incidents and information security: IR-04, IR-05, IR-06, IR-09, SI-04, SI-05 (75%)
- 16.3 Reporting to health regulators and data subjects: IR-06, PM-15, PM-26, PT-04, PT-05 (72%)
- 17.1 Clinical service continuity planning: CP-01, CP-02, CP-03, CP-04, CP-05, PM-08, PM-11 (82%)
- 17.2 Information security continuity for patient care: CP-02, CP-06, CP-07, CP-08, CP-09, CP-10, CP-11, CP-12, CP-13 (85%)
- 17.3 Redundancy for critical clinical systems: CP-06, CP-07, CP-08, SC-36, PE-09, PE-11 (88%)
- 18.1 Legal and regulatory requirements for health data: PL-04, PM-01, SA-04, PT-01, PT-02, PT-04, PT-05 (72%)
- 18.2 Patient consent and health data sharing controls: PT-04, PT-05, PT-02, PT-03, PT-06, PT-07, PM-25, PM-26, PM-27 (68%)
- 18.3 Health information security reviews and audits: CA-01, CA-02, CA-05, CA-07, CA-08, PM-06, PM-14 (85%)
- 18.4 Technical compliance for health systems: CA-02, CA-08, RA-05, SI-02, CM-06 (85%)
- H.1 Patient safety integration with information security: PM-01, PM-09, PM-11, RA-03, PL-02 (60%)
- H.2 Health information exchange security: CA-03, SC-07, SC-08, SC-12, SC-13, AC-04, AC-20, SC-46 (72%)
- H.3 Medical device security management: CM-08, RA-05, SI-02, SC-07, MA-01, MA-02, MA-06, SR-11 (68%)
- H.4 Research data and biobank security: AC-03, AC-04, AC-06, SI-19, PT-04, PT-06, PT-07, SC-28, AU-02, AU-03 (70%)
- H.5 Telehealth and remote clinical services security: AC-17, SC-08, SC-13, SC-23, IA-02, IA-08, AU-02 (75%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=iso_27799
- Control-to-clause mappings as JSON: /api/v1/frameworks/iso_27799?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/iso-27799.json
- Page for people: /frameworks/iso-27799/
