Clinic and practice
Reception and consulting-room PCs, a practice or pharmacy system, diagnostic equipment with a PC inside it, and a link to the record system.
How the register reads it
| Also called | GP practice, surgery, pharmacy, care home |
|---|---|
| Family | Branch, office and data centre |
| Exposure by default | Attended: staffed when open; equipment in consulting rooms is reachable by patients when a clinician steps out. A line that says attended, unattended, public or hostile (outdoors, in transit, at sea) overrides it. |
| Link by default | Always: a wired link, with paper as the fallback. A line that names the link (fibre, 4G, satellite, radio, offline) overrides it. |
| Regulated data by default | Personal, health; a line that names the data overrides it. |
| Runs plant | Not by default; a line that names PLCs, SCADA, RTUs or HMIs adds it. |
| What a loss costs | A clinic offline sees patients from memory and paper; a clinic PC lost holds the most protected data category there is. |
| Contract focus | Medical-device update terms, record-system availability, secure disposal of imaging and diagnostic equipment. |
What each regime attaches
16 clauses across 7 regimes, on the class defaultsShown on a register for the regimes you tick, by the exposure, link, data and plant the line states; with none ticked, the ISO 27001 rows are the default. Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022, with the 27002:2022 guidance beside it
Attaches to every site: the off-premises, equipment, media, endpoint, backup, redundancy, network and continuity controls of Annex A, by the site's exposure, link, data and plant. With nothing ticked these rows render as the default.
ISO 27001 5.14 Information transferPut rules, procedures or agreements in place for every way information moves, inside and outside the organization.
ISO 27002 5.14 guidance: Requires transfer rules, procedures or agreements to be in place for every type of transfer facility, covering transfers within the organisation and between the organisation and outside parties.
Common gap: Reliance on informal verbal agreements
Source framework: ISO/IEC 27001:2022
ISO 27001 7.9 Security of assets off-premisesProtect assets used or held off-site.
ISO 27002 7.9 guidance: Requires assets located away from the organisation's premises to be protected.
Common gap: Missing offsite asset register
Source framework: ISO/IEC 27001:2022
ISO 27001 7.10 Storage mediaManage storage media across acquisition, use, transport and disposal per classification and handling rules.
ISO 27002 7.10 guidance: Requires storage media to be managed across their whole life cycle, covering acquisition, use, transportation and disposal, in accordance with the organisation's classification scheme and handling requirements. Older source material adds that disposal should follow formal procedures scaled to the sensitivity of the information held, and that media in transit needs protection against unauthorised access, misuse and corruption.
Common gap: No documented classification for media
Source framework: ISO/IEC 27001:2022
ISO 27001 7.13 Equipment maintenanceMaintain equipment correctly to preserve availability, integrity and confidentiality.
ISO 27002 7.13 guidance: Requires equipment to be maintained correctly, so that information stays available, intact and confidential.
Common gap: no documented maintenance schedule
Source framework: ISO/IEC 27001:2022
ISO 27001 8.9 Configuration managementEstablish, document, implement, monitor and review secure configurations for hardware, software, services and networks.
ISO 27002 8.9 guidance: Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a standing process that keeps systems configured securely and consistently.
Common gap: outdated baselines
Source framework: ISO/IEC 27001:2022
ISO 27001 8.24 Use of cryptographyDefine and implement rules for effective use of cryptography and key management.
ISO 27002 8.24 guidance: Requires defined and implemented rules on using cryptography effectively, including how cryptographic keys are managed.
Common gap: Missing documented key lifecycle
Source framework: ISO/IEC 27001:2022
NIST SP 800-53 Rev 5
Attaches to every site: the PE family for the premises and the alternate work site, MP for the media, AC-17, AC-19 and AC-20 for remote access, mobile devices and external systems, the CP family for the sites that lose their link, SC-7 for the boundary and SI-7 and CM-8 for what runs there.
SP 800-53 CM-8 System component inventoryRequires an accurate inventory of system components that covers every component, avoids duplicate or cross system accounting, is held at the granularity needed for tracking and reporting, carries the information the organization has defined for accountability, and is reviewed and updated on a defined frequency.
Common gap: Cloud and container assets absent because inventory is built from a fixed asset register
Source framework: NIST SP 800-53 Rev 5
SP 800-53 MP-4 Media storageRequires organization-defined media types to be physically controlled and securely stored within organization-defined controlled areas, and requires that protection to continue until the media is destroyed or sanitised using approved equipment, techniques and procedures.
Common gap: Media awaiting destruction accumulates in unsecured areas for months
Source framework: NIST SP 800-53 Rev 5
SP 800-53 MP-5 Media transportRequires organization-defined media types to be protected and controlled by defined controls while in transit outside controlled areas, accountability for the media to be maintained throughout, transport activity to be documented, and transport to be carried out only by authorized personnel.
Common gap: Backup media couriered with a signature on collection but no custody record in between
Source framework: NIST SP 800-53 Rev 5
SP 800-53 PE-3 Physical access controlRequires physical access authorizations to be enforced at defined entry and exit points by verifying authorization before entry and controlling ingress and egress with defined mechanisms or guards, physical access audit logs to be kept, publicly accessible areas to be controlled, visitors to be escorted and their activity controlled in defined circumstances,...
Common gap: Tailgating unaddressed, so an authorization check happens for only the first person through
Source framework: NIST SP 800-53 Rev 5
SP 800-53 SI-7 Software, firmware, and information integrityRequires integrity verification tools to be employed to detect unauthorized changes to organization-defined software, firmware and information, and requires organization-defined actions to be taken when such unauthorized changes are detected.
Common gap: Integrity monitoring produces constant noise from routine change and is therefore ignored
Source framework: NIST SP 800-53 Rev 5
CIS Controls v8
Attaches to every site: the asset inventory on all of them, anti-malware on the unattended and public ones and on plant, automated and isolated backups where the link is intermittent or absent, remote wipe and the VPN on portable and remote devices.
CIS v8 CIS-1.1 Establish and Maintain Detailed Enterprise Asset InventoryEstablish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, enterp...
Common gap: Safeguard implemented for some assets but not all in scope
Source framework: CIS Controls v8
ISO 22301:2019
Attaches the business continuity plans and procedures to every site, and the plan content and recovery clauses to the sites whose link is intermittent or absent.
ISO 22301 8.4.1 GeneralImplement and maintain a response structure enabling timely warning and communication to relevant interested parties, with plans and procedures to manage the organization through a disruption and to activate continuity solutions, identified and documented from the output of the selected strategies and solutions, and with procedures that are specific about im...
Common gap: Procedures written for one rehearsed scenario, brittle against anything else
Source framework: ISO 22301:2019
The GDPR, Chapter V transfers and Article 32
Attaches Article 32 to every site that holds personal or health data, and Articles 44 to 46 to a site outside the EEA and the United Kingdom that handles personal data of EU or UK persons, read from the home jurisdiction in the preamble and the site's country.
GDPR Art. 32 Security of processingImplement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include,...
Common gap: Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures
Source framework: GDPR (Regulation (EU) 2016/679)
DORA, the Digital Operational Resilience Act
Attaches Article 11 (response and recovery) to every site of a financial entity and Article 12 (backup, restoration and recovery) to the sites whose link is intermittent or absent; a site with no recovery objective is a finding.
DORA Art. 11 Response and recoveryFinancial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
Common gap: No ICT continuity/response/recovery plans
Source framework: DORA (Regulation (EU) 2022/2554)
NIST SP 800-207, zero trust architecture
Attaches the satellite-facility deployment scenario to every site and the two design tenets (every communication secured, every asset's posture monitored) to the sites where remote access is named. No regime page: it renders on the remote-access rows and the finding.
SP 800-207 SC-SATELLITE Deployment Scenario: Enterprise with Satellite FacilitiesApplies ZTA to an organization with a headquarters plus geographically dispersed locations and remote workers that have no full enterprise-owned network.
Common gap: VPN-only model treated as zero trust
Source framework: NIST SP 800-207
Questions for the hardware vendor
six, and one for the classFor the consulting-room and reception PCs and the diagnostic units, over the fixed link:
- Can you show measured boot or firmware attestation on the equipment, and how a failed check reports back over the fixed link?
- How does the equipment take an update unattended over the fixed link, and how does it roll back on its own when the update fails part way?
- Can a lost or stolen unit be wiped remotely, and what happens to the wipe command while the unit is offline?
- Is local storage on the equipment encrypted at rest with the key held off the device, and can that be verified from the fleet console?
- Can the equipment be recovered to a known state by a non-technical person on site, without a technician's visit?
- What spares, lead times and end-of-support dates apply to the equipment, and who holds the spares nearest the site?
For this class: Which diagnostic units carry an embedded PC that cannot take an update, and how is each one isolated?
Findings this class can raise
- Personal data at a site outside the home area
A site outside the EEA and the United Kingdom that handles personal data of EU or UK persons, read from the preamble's home jurisdiction and the site's country. Chapter V of the GDPR governs the transfer: an adequacy decision, appropriate safeguards or a derogation, with the security duty of Article 32 beside it. The register names the site and the country; whether a transfer mechanism is in place is what the line does not say. - Concentration in one class or one link type
One site class holding a third or more of the sites (three or more of them), or a single link type across every site: the register names the share so the dependence is a recorded one. A failure mode shared by every site (one carrier, one device model, one class) is what the continuity and redundancy duties ask to be planned for, not avoided. - Financial entity site with no recovery objective
DORA is ticked and the line carries no recovery time objective. Articles 11 and 12 ask a financial entity to hold response and recovery plans and backup and restoration procedures with recovery objectives for its ICT systems, wherever they run; a branch, an ATM estate or an outsourcing site without one is a gap in the plan, not in the site. - Hardware questions unanswered
On the first paste no line answers the six questions the register puts to the vendor of the hardware at each site: attestation of firmware and boot, unattended update and rollback, remote wipe, local storage encryption, recovery without a technician, spares; each class adds one question of its own. The finding is the RFI page: the questions per site, grouped by class, ready to paste into the next rollout's request.
Do this for every site on your list
Paste the list and get this reading for every site at once, with the link, the exposure, the data held, the findings and the duty rows per regime. Eight sites free, no account.
Build my edge register