Disclose and operate physical security + workstation security + media controls + backup and disaster recovery features per MDS2 PLOK + DTBK sections and related legacy MDS2-17 to MDS2-20. Physical Locks (PLOK) including device chassis locks + USB port locks + cable locks + tamper-evident seals + facility access controls + security cameras + alarm systems. Workstation security including operating-system user account controls + screen locks + clinical-workflow consideration + cleaning and disinfection protocols + ergonomic considerations. Device and Media Controls including portable media restrictions + media sanitisation per NIST 800-88 (clear + purge + destroy) + chain-of-custody for media + secure transport + media accountability. Disposal and re-use procedures including end-of-life sanitisation + decommissioning workflow + asset disposal certificate + environmental compliance + lithium-ion battery handling. Data Backup and Disaster Recovery (DTBK) including backup frequency + backup retention + backup encryption + backup integrity verification + restore procedures + recovery time objective (RTO) + recovery point objective (RPO) + geographically separated backup + clinical-continuity planning + offline backup option for ransomware resilience.
This control maps to 84 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 84 it maps to, and the evidence behind each claim, over MCP and REST.