WHO Global Strategy on Digital Health 2020-2025
Strategic Objective 2: Advance Country Digital Health Implementation

WHO Global Strategy on Digital Health 2020-2025 SO2.2: Digital health architecture blueprint

Define a national digital health architecture blueprint or roadmap for implementation.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 212 controls across 97 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • RMD-1 Reference Data Management

ISO 22320:2018 · 3 controls

ISO/IEC 23894:2023 · 3 controls

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 27014:2020 · 3 controls

ISO/IEC 27400:2022 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 29147:2018 · 3 controls

ISO/IEC 30111:2019 · 3 controls

  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 56002 · 2 controls

  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation

SOC 2 · 2 controls

  • SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner
  • SOC2-CC7.4 Responds to identified security incidents through defined procedures
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage

UK Bribery Act 2010 · 2 controls

  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

  • FFIEC-05 Roles and responsibilities definition

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27043 · 1 control

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27003:2017 · 1 control

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/SAE 21434 · 1 control

NIST SP 800-190 · 1 control

  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,

PCI P2PE · 1 control

PCI PIN Security · 1 control

PCI SSF · 1 control

  • SCA-S2 Interpretation and Definitions

South Korea ISMS-P · 1 control

  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)

WCAG 2.2 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Strategic Objective 2: Advance Country Digital Health Implementation

Query this from an agent

The graph holds this control, the 212 it maps to, and the evidence behind each claim, over MCP and REST.