ISO 27799:2016
Health informatics — Information security management in health using ISO/IEC 27002
Health informatics — Information security management in health using ISO/IEC 27002
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 99
- Дата публикации:
- 1 июля 2016 г.
- Издание:
- ISO IS 27799 edition 2 version 1
- ICS:
- 35.240.80
ISO 27799:2016 gives guidelines for organizational information security standards and information security management practices including the selection, implementation and management of controls taking into consideration the organization's information security risk environment(s). It defines guidelines to support the interpretation and implementation in health informatics of ISO/IEC 27002 and is a companion to that International Standard. ISO 27799:2016 provides implementation guidance for the controls described in ISO/IEC 27002 and supplements them where necessary, so that they can be effectively used for managing health information security. By implementing ISO 27799:2016, healthcare organizations and other custodians of health information will be able to ensure a minimum requisite level of security that is appropriate to their organization's circumstances and that will maintain the confidentiality, integrity and availability of personal health information in their care. It applies to health information in all its aspects, whatever form the information takes (words and numbers, sound recordings, drawings, video, and medical images), whatever means are used to store it (printing or writing on paper or storage electronically), and whatever means are used to transmit it (by hand, through fax, over computer networks, or by post), as the information is always be appropriately protected. ISO 27799:2016 and ISO/IEC 27002 taken together define what is required in terms of information security in healthcare, they do not define how these requirements are to be met. That is to say, to the fullest extent possible, ISO 27799:2016 is technology-neutral. Neutrality with respect to implementing technologies is an important feature. Security technology is still undergoing rapid development and the pace of that change is now measured in months rather than years. By contrast, while subject to periodic review, International Standards are expected on the whole to remain valid for years. Just as importantly, technological neutrality leaves vendors and service providers free to suggest new or developing technologies that meet the necessary requirements that ISO 27799:2016 describes. As noted in the introduction, familiarity with ISO/IEC 27002 is indispensable to an understanding of ISO 27799:2016. The following areas of information security are outside the scope of ISO 27799:2016: a) methodologies and statistical tests for effective anonymization of personal health information; b) methodologies for pseudonymization of personal health information (see Bibliography for a brief description of a Technical Specification that deals specifically with this topic); c) network quality of service and methods for measuring availability of networks used for health informatics; d) data quality (as distinct from data integrity).
Abstract
Overview
ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and interprets the controls of ISO/IEC 27002 for healthcare, helping organizations select, implement and manage security controls appropriate to their risk environment. ISO 27799 is technology‑neutral and applies to health data in any form (paper, images, recordings, electronic records) and across any transmission or storage method.
Key topics and technical requirements
ISO 27799 supplements ISO/IEC 27002 with healthcare-focused guidance. Major topics covered include:
- Information security policies: management direction and regular policy review.
- Organization of information security: roles, segregation of duties, project security, mobile devices and teleworking.
- Human resource security: pre-employment screening, training, responsibilities, and termination procedures.
- Asset management: inventory, ownership, acceptable use, classification, labelling and media handling.
- Access control: business requirements, user provisioning, privileged access management, authentication and access reviews.
- Cryptography: policy for cryptographic controls and key management guidance.
- Physical & environmental security: secure areas, entry controls, equipment siting and protection.
- Operations security: change management, backup, malware protection, logging, vulnerability management and audit considerations.
- Communications security and additional controls tailored to health informatics contexts.
Important clarifications:
- ISO 27799 and ISO/IEC 27002 together define what is required but not exactly how to implement it - they are technology‑neutral.
- Out of scope: anonymization/pseudonymization methodologies, network QoS measurement, and data quality (distinct from data integrity).
Applications and who uses it
ISO 27799 is practical for:
- Healthcare providers (hospitals, clinics) implementing information security for electronic health records (EHRs).
- Health information custodians and data controllers responsible for patient data confidentiality, integrity and availability.
- Health IT vendors and system integrators designing secure clinical systems.
- Risk managers, security officers and compliance teams aligning controls to clinical workflows.
- Auditors and assessors evaluating health-sector information security controls.
Benefits include standardized guidance for protecting personal health information, clearer risk‑based control selection, and better alignment with general information security frameworks.
Related standards
- ISO/IEC 27002 - Code of practice for information security controls (primary companion).
- ISO/IEC 27001 - Information security management systems (ISMS) - often used alongside ISO 27799 for certification and management-system alignment.
Keywords: ISO 27799, health informatics, information security, ISO/IEC 27002, health data security, personal health information, access control, cryptography, asset management, healthcare cybersecurity.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- ISO 27799:2016
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…