ISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence
Resource Requirements

ISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence 6.5: Preparing and Distributing Audit Report

Audit team leader prepares audit report and distributes it within agreed time to defined recipients.

What else in your programme already covers this

This control maps to 468 controls across 210 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27011:2024 · 7 controls

  • CPNI-64.2001_2003 Basis, purpose and definitions (47 CFR 64.2001 + 64.2003)
  • CPNI-64.2004 Customer approval mechanisms - opt-in and opt-out (47 CFR 64.2004)
  • CPNI-64.2010 Safeguards on disclosure - authentication for account access (47 CFR 64.2010)
  • CPNI-64.2011 Notification of CPNI security breaches (47 CFR 64.2011)
  • CPNI-AnnualCert Annual compliance certification - 1 March deadline (47 CFR 64.2009(e))

ISO/IEC 27400:2022 · 5 controls

  • 3.3 Configure Data Access Control Lists
  • 3.7 Establish and Maintain a Data Classification Scheme
  • 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data
  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary
  • NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C
  • RG5.71-C.3 Cyber Security Training
  • RG5.71-C.5 Recovery and Restoration
  • RG5.71-C.6 Configuration Management
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • DSO-3 Data Access Management
  • RMD-1 Reference Data Management
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-53 Rev 5 · 4 controls

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity

ACSC Essential Eight · 3 controls

  • E8-MFA-ML1 Multi-Factor Authentication - Maturity Level 1
  • E8-MFA-ML2 Multi-Factor Authentication - Maturity Level 2
  • E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3
  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists

ISO 19011:2018 · 3 controls

  • 6.5 Preparing and distributing audit report
  • 6.5.1 Preparing audit report
  • 6.5.2 Distributing audit report

ISO 22320:2018 · 3 controls

ISO/IEC 23894:2023 · 3 controls

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27014:2020 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 29147:2018 · 3 controls

ISO/IEC 30111:2019 · 3 controls

MTCS (Singapore) · 3 controls

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • ORANWG11-6 Security Test Specifications, Certification, and Conformance
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

OWASP Top 10:2025 · 3 controls

  • PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training
  • PICSGMP-5 Chapter 5: Production Operations and Material Management
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management

UK Bribery Act 2010 · 3 controls

  • VP-2 Holder Binding
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)
  • W3CVCDM-4 Accessibility, Internationalization, Security
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training

FIDO2 / WebAuthn · 2 controls

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

FedRAMP Rev 5 · 2 controls

ISMAP (Japan) · 2 controls

ISO 13485 · 2 controls

  • 6.4 Logging and Monitoring
  • ISO13485-12 Unique user identification and authentication

ISO 19011 · 2 controls

  • 6.4 Logging and Monitoring
  • 6.7 Conducting Audit Follow-up

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO 27043 · 2 controls

ISO 56002 · 2 controls

ISO/SAE 21434 · 2 controls

MARS-E · 2 controls

MITRE ATT&CK · 2 controls

MITRE D3FEND · 2 controls

  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NISTSP115-1 Scope, Methodology, and Assessment Planning
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 2 controls

  • NISTSP123-3 Authentication, Access Control, and Account Management
  • NISTSP123-8 Governance, Policies, and ISMS Integration

NIST SP 800-137 · 2 controls

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment
  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-145 · 2 controls

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework
  • NISTSP146-6 Cloud Security and Privacy Recommendations

NIST SP 800-190 · 2 controls

NIST SP 800-61 · 2 controls

  • NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 2 controls

  • NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection
  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators

NIST SP 800-92 · 2 controls

  • NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities

OWASP ASVS · 2 controls

  • OWASPASVS-1 Architecture, Design and Threat Modelling (V1)
  • OWASPASVS-2 Authentication and Credential Storage (V2 + V2.4)

OWASP MASVS · 2 controls

OWASP SAMM · 2 controls

  • OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions
  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)

OpenSSF Scorecard · 2 controls

  • OSSFSC-1 Branch Protection, Code Review, and Repository Governance
  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports

PTES · 2 controls

  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-6 Phased Application and Enforcement

SOC 2 · 2 controls

  • SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner
  • SOC2-CC7.4 Responds to identified security incidents through defined procedures
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage

South Korea ISMS-P · 2 controls

  • 4.4.1 Resources, Roles, Responsibility, and Authority

BSI IT-Grundschutz · 1 control

  • BSI-03 Multi-factor authentication requirements
  • BE-CF-03 Multi-factor authentication requirements

COBIT 2019 · 1 control

  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

FDA 21 CFR Part 11 · 1 control

  • Part11.300 Controls for identification codes and passwords (21 CFR §11.300)
  • QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10)
  • FFIEC-05 Roles and responsibilities definition

FISMA · 1 control

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections

GLBA · 1 control

HKMA SPM · 1 control

  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor

ISO 27799 · 1 control

  • ISO27799-12 Unique user identification and authentication

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27003:2017 · 1 control

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27031:2011 · 1 control

  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NIS2I-6 Access Control, Asset Management, and Physical Security
  • PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature
  • NISTPF-5 Protect-P Access Control (PR.AC-P)

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards

OSFI B-13 · 1 control

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OWASPAPI-2 Broken Authentication and Token Management
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,

PCI P2PE · 1 control

PCI PIN Security · 1 control

PCI SSF · 1 control

PSD2 SCA · 1 control

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PNGCYBER-3 NICTA Oversight and Computer Emergency Response Team (CERT) Coordination
  • PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices)
  • PSPF24-1 Security Culture, Governance, Risk Management
  • RCEPEC-1 Online Personal Information Protection (12.13)

SLSA · 1 control

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SIGSTORE-2 Transparency Log (Rekor) and Verification
  • SCA-S2 Interpretation and Definitions

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)

WCAG 2.2 · 1 control

  • SO2.2 Digital health architecture blueprint

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Resource Requirements

Query this from an agent

The graph holds this control, the 468 it maps to, and the evidence behind each claim, over MCP and REST.