ISO 27799:2025
ISO/TC 215's application of ISO/IEC 27002:2022 to health: which of the 93 controls apply unchanged, which carry guidance for health, which are supplemented with a health control and purpose, and the eight HLT controls the standard adds, with the 22 Annex A shall statements a health organization writes into its ISO/IEC 27001 Statement of Applicability. 73 leaves read in the complete ISO/DIS 27799:2025 at 85; the published third edition is not held.
ISO 27799:2025 is a compliance framework from International (ISO/TC 215) with 4 domains and 73 controls that map to 223 other frameworks. The largest domains are Clause 5: Organizational controls for health – ISO 27799:2025 (31 controls), Clause 8: Technological controls for health – ISO 27799:2025 (23 controls), Clause 7: Physical controls for health – ISO 27799:2025 (10 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
Clause 5: Organizational controls for health – ISO 27799:2025
| Code | Title |
|---|---|
| iso-27799-2025::5.1 | 5.1 Policies for information security |
| iso-27799-2025::5.11 | 5.11 Return of assets |
| iso-27799-2025::5.12 | 5.12 Classification of information |
| iso-27799-2025::5.13 | 5.13 Labelling of information |
| iso-27799-2025::5.14 | 5.14 Information transfer |
| iso-27799-2025::5.15 | 5.15 Access control |
| iso-27799-2025::5.16 | 5.16 Identity management |
| iso-27799-2025::5.17 | 5.17 Authentication information |
| iso-27799-2025::5.18 | 5.18 Access rights |
| iso-27799-2025::5.19 | 5.19 Information security in supplier relationships |
| iso-27799-2025::5.2 | 5.2 Information security roles and responsibilities |
| iso-27799-2025::5.21 | 5.21 Managing information security in the ICT supply chain |
| iso-27799-2025::5.23 | 5.23 Information security for use of cloud services |
| iso-27799-2025::5.24 | 5.24 Information security incident management planning and preparation |
| iso-27799-2025::5.25 | 5.25 Assessment and decision on information security events |
| iso-27799-2025::5.28 | 5.28 Collection of evidence |
| iso-27799-2025::5.3 | 5.3 Segregation of duties |
| iso-27799-2025::5.30 | 5.30 ICT readiness for business continuity |
| iso-27799-2025::5.34 | 5.34 Privacy and protection of PII |
| iso-27799-2025::5.35 | 5.35 Independent review of information security |
| iso-27799-2025::5.36 | 5.36 Conformance with policies, rules and standards for information security |
| iso-27799-2025::5.38 | 5.38 HLT: Information security requirements analysis and specification |
| iso-27799-2025::5.39 | 5.39 HLT: Uniquely identifying subjects of care |
| iso-27799-2025::5.40 | 5.40 HLT: Validation of displayed and printed data |
| iso-27799-2025::5.41 | 5.41 HLT: Publicly available health information |
| iso-27799-2025::5.42 | 5.42 HLT: Emergency communication |
| iso-27799-2025::5.43 | 5.43 HLT: External incident reporting |
| iso-27799-2025::5.6 | 5.6 Contact with special interest groups |
| iso-27799-2025::5.7 | 5.7 Threat intelligence |
| iso-27799-2025::5.8 | 5.8 Information security in project management |
| iso-27799-2025::5.9 | 5.9 Inventory of information and other associated assets |
Clause 6: People controls for health – ISO 27799:2025
| Code | Title |
|---|---|
| iso-27799-2025::6.1 | 6.1 Screening |
| iso-27799-2025::6.2 | 6.2 Terms and conditions of employment |
| iso-27799-2025::6.3 | 6.3 Information security awareness, education and training |
| iso-27799-2025::6.4 | 6.4 Disciplinary process |
| iso-27799-2025::6.5 | 6.5 Responsibilities after termination or change of employment |
| iso-27799-2025::6.6 | 6.6 Confidentiality or non-disclosure agreements |
| iso-27799-2025::6.7 | 6.7 Remote working |
| iso-27799-2025::6.8 | 6.8 Information security event reporting |
| iso-27799-2025::6.9 | 6.9 HLT: Management training |
Clause 7: Physical controls for health – ISO 27799:2025
| Code | Title |
|---|---|
| iso-27799-2025::7.1 | 7.1 Physical security perimeters |
| iso-27799-2025::7.10 | 7.10 Storage media |
| iso-27799-2025::7.11 | 7.11 Supporting utilities |
| iso-27799-2025::7.12 | 7.12 Cabling security |
| iso-27799-2025::7.13 | 7.13 Equipment maintenance |
| iso-27799-2025::7.14 | 7.14 Secure disposal or re-use of equipment |
| iso-27799-2025::7.2 | 7.2 Physical entry |
| iso-27799-2025::7.7 | 7.7 Clear desk and clear screen |
| iso-27799-2025::7.8 | 7.8 Equipment siting and protection |
| iso-27799-2025::7.9 | 7.9 Security of assets off-premises |
Clause 8: Technological controls for health – ISO 27799:2025
| Code | Title |
|---|---|
| iso-27799-2025::8.1 | 8.1 User endpoint devices |
| iso-27799-2025::8.10 | 8.10 Information deletion |
| iso-27799-2025::8.11 | 8.11 Data masking |
| iso-27799-2025::8.13 | 8.13 Information backup |
| iso-27799-2025::8.15 | 8.15 Logging |
| iso-27799-2025::8.18 | 8.18 Use of privileged utility programs |
| iso-27799-2025::8.19 | 8.19 Installation of software on operational systems |
| iso-27799-2025::8.2 | 8.2 Privileged access rights |
| iso-27799-2025::8.21 | 8.21 Security of network services |
| iso-27799-2025::8.22 | 8.22 Segregation of networks |
| iso-27799-2025::8.23 | 8.23 Web filtering |
| iso-27799-2025::8.24 | 8.24 Use of cryptography |
| iso-27799-2025::8.26 | 8.26 Application security requirements |
| iso-27799-2025::8.29 | 8.29 Security testing in development and acceptance |
| iso-27799-2025::8.31 | 8.31 Separation of development, test and production environments |
| iso-27799-2025::8.32 | 8.32 Change management |
| iso-27799-2025::8.33 | 8.33 Test information |
| iso-27799-2025::8.35 | 8.35 HLT: Zero trust principles |
| iso-27799-2025::8.5 | 8.5 Secure authentication |
| iso-27799-2025::8.6 | 8.6 Capacity management |
| iso-27799-2025::8.7 | 8.7 Protection against malware |
| iso-27799-2025::8.8 | 8.8 Management of technical vulnerabilities |
| iso-27799-2025::8.9 | 8.9 Configuration management |
Your Compliance Coverage
If you comply with ISO 27799:2025, you already cover:
NIST SP 800-66
10%
12 controls mapped
Compare →MDS2 (Medical Device)
10%
12 controls mapped
Compare →MARS-E
10%
12 controls mapped
Compare →+ 220 more: ISO 13485 (10%), NIST Privacy Framework (9%)
See all 223 mapped frameworks ↓Maps to 223 other frameworks
Coverage is not the same as your position
This page shows what ISO 27799:2025 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is ISO 27799:2025 and who does it apply to?
ISO 27799:2025 is a compliance framework from International (ISO/TC 215) with 4 domains and 73 controls. ISO/TC 215's application of ISO/IEC 27002:2022 to health: which of the 93 controls apply unchanged, which carry guidance for health, which are supplemented with a health control and purpose, and the eight HLT controls the standard adds, with the 22 Annex A shall statements a health organization writes into its ISO/IEC 27001 Statement of Applicability. 73 leaves read in the complete ISO/DIS 27799:2025 at 85; the published third edition is not held. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO 27799:2025 actually require?
ISO 27799:2025 has 73 controls organised across 4 domains. The largest domains are Clause 5: Organizational controls for health – ISO 27799:2025 (31 controls), Clause 8: Technological controls for health – ISO 27799:2025 (23 controls), Clause 7: Physical controls for health – ISO 27799:2025 (10 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO 27799:2025 do I already cover?
ISO 27799:2025 maps to 223 other compliance frameworks. The top mapping partners are NIST SP 800-66 (10% coverage), MDS2 (Medical Device) (10% coverage), MARS-E (10% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO 27799:2025?
Start your ISO 27799:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 27799:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 73 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required