MDS2 (Medical Device)
Physical Security Workstation Disposal and Backup - MDS2

MDS2 (Medical Device) MDS2-Physical-Security-PLOK-Workstation-Disposal-Backup-DTBK-Disaster-Recovery: MDS2 Physical Security + PLOK + Workstation + Disposal + Backup + DTBK + Disaster Recovery

Disclose and operate physical security + workstation security + media controls + backup and disaster recovery features per MDS2 PLOK + DTBK sections and related legacy MDS2-17 to MDS2-20. Physical Locks (PLOK) including device chassis locks + USB port locks + cable locks + tamper-evident seals + facility access controls + security cameras + alarm systems. Workstation security including operating-system user account controls + screen locks + clinical-workflow consideration + cleaning and disinfection protocols + ergonomic considerations. Device and Media Controls including portable media restrictions + media sanitisation per NIST 800-88 (clear + purge + destroy) + chain-of-custody for media + secure transport + media accountability. Disposal and re-use procedures including end-of-life sanitisation + decommissioning workflow + asset disposal certificate + environmental compliance + lithium-ion battery handling. Data Backup and Disaster Recovery (DTBK) including backup frequency + backup retention + backup encryption + backup integrity verification + restore procedures + recovery time objective (RTO) + recovery point objective (RPO) + geographically separated backup + clinical-continuity planning + offline backup option for ransomware resilience.

What else in your programme already covers this

This control maps to 84 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 3 controls

ISO 13485 · 3 controls

ISO 27019 · 3 controls

ISO 27043 · 3 controls

ISO 27799 · 3 controls

ISO/SAE 21434 · 3 controls

ISO/IEC 27010:2015 · 2 controls

ISO/IEC 27011:2024 · 2 controls

OWASP ASVS · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

South Korea ISMS-P · 2 controls

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Bahrain PDPL · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • 62351-8 Role-based access control (RBAC)

ISO 20000-1 · 1 control

ITIL 4 · 1 control

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

  • NIS2I-6 Access Control, Asset Management, and Physical Security
  • 3.10 Encrypt Sensitive Data in Transit
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP Top 10:2025 · 1 control

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

South Korea PIPA · 1 control

Turkey KVKK · 1 control

  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 84 it maps to, and the evidence behind each claim, over MCP and REST.