Frameworks / ISO 27799 / 01 ISO 27799
ISO 27799: Patient Data Protection
ISO 27799 01: ePHI access controls and authorization ePHI access controls and authorization. Control from ISO 27799 framework, domain: ISO 27799: Patient Data Protection.
What else in your programme already covers this This control maps to 231 controls across 123 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) NAIC-2 Information Security Program (ISP) - Section 4 NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 3.10 Encrypt Sensitive Data in Transit 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles SUPCHAIN-1 Build Integrity - Source, Build, Provenance SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SOC2-CC6.2 Prior to granting access, registration and authorization processes are established SOC2-CC6.3 Role-based access and least privilege are enforced SAM-1 Customer Information Confidentiality (Section 48) SAM-6 Legal Authorization Requirements APPI-A26 Report of Leakage to the Commission and Notification to the Person FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) 62351-8 Role-based access control (RBAC) NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NIST190-08 Privileged access in cloud environments NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NHPA-7 Data Protection Assessments and Processor Contracts NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training NZPRV-2 IPP 5 Storage and Security of Personal Information SOC-CY-S1 Logical and Physical Access Controls CISABD-1 Take Ownership of Customer Security Outcomes SIGSTORE-2 Transparency Log (Rekor) and Verification TSAPIPE-2 OT/IT Network Segmentation and Access Control UGA-10 Sensitive Personal Data Prohibition URUGUAY-3 Sensitive Data, Health Data, Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in ISO 27799: Patient Data Protection Query this from an agent The graph holds this control, the 231 it maps to, and the evidence behind each claim, over MCP and REST.