ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
General requirements – ISO/IEC 17025:2017 - General Requirements for Testing and Calibration

ISO/IEC 17025:2017 - General Requirements for Testing and Calibration 4.2: Confidentiality

Through commitments that can be enforced in law, the laboratory is responsible for managing all information it obtains or produces while carrying out its activities. It tells the customer beforehand what information it plans to make public, and treats all other information as proprietary and confidential, except what the customer itself makes public or where laboratory and customer have agreed otherwise. Where law or contractual arrangements require the laboratory to release confidential information, it tells the customer or person concerned what is being released, unless the law forbids this. Information about the customer that comes from someone other than the customer (for example a complainant or a regulator) is kept confidential, shared only by customer and laboratory, and the laboratory does not reveal who provided it unless that source agrees. Staff, committee members, contractors, staff of external bodies and anyone else acting for the laboratory keep information confidential except where the law requires otherwise.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 14 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 3 controls

  • C5-HR-06 Confidentiality agreements
  • C5-IDM-08 Confidentiality of authentication information
  • C5-PSS-07 Confidentiality of Authentication Information
  • CSL-Art40 Confidentiality of User Information - Art. 40

ISO 27001:2022 · 1 control

  • 6.6 Confidentiality or non-disclosure agreements

ISO 27002:2022 · 1 control

  • 6.6 Confidentiality or non-disclosure agreements

ISO 27018:2019 · 1 control

  • 13.2.4 Confidentiality or non-disclosure agreements
  • ISO37002-8.7 Confidentiality and Data Protection

ISO/IEC 29147:2018 · 1 control

  • 29147-5.8 Confidentiality of Reports

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in General requirements – ISO/IEC 17025:2017 - General Requirements for Testing and Calibration

Query this from an agent

The graph holds this control, the 14 it maps to, and the evidence behind each claim, over MCP and REST.