Skip to main content
Beta version A NHS service powered by standards. Feedbackopens in a new window will help us improve.

Health informatics — Information security management in health using ISO/IEC 27002

This International Standard gives guidelines for organizational information security standards and information security management practices.

About this standard

Publisher
ISO/TC215
Reference code
ISO 27799:2016
Publication date
1 January 2016
Status
Active
Show definitions of statuses

Future Standards. If the selected standard is a Future standard, show only statuses for Future standards.

Proposed. New standards suggested to address unmet need(s), but further exploratory work is required.

Draft in Progress. Standards that are in the process of being developed or going through consultation.

On Hold. Standards that have been paused but may resume in future.

Withdrawn. Standards that have been withdrawn from any development and approval process.

Standard type
Information standards
Show definitions of standard types

Collections. A Collection is a systematic gathering of a specified selection of data or information for a particular stated purpose from existing records held within health and care systems and electronic devices.

Extractions. An extraction is a type of collection that is pulled from an operational system by the data controller and transmitted to the receiver without additional processing or transcription by the sender.

Information standards. Information standards are agreed ways of doing something, written down as a set of precise criteria so they can be used as rules, guidelines, or definitions.

Technical Standards and specifications. Technical standards and specifications specify how to make information available technically including how the data is structured and transported.

Contact point

https://www.iso.org/committee/54960.html

Documentation
View documentation for this standard
opens in a new tab
(opens in new tab)
Applies to
  • Digital Health Agencies and NGOs
  • Vendors
  • Healthcare Administrators and Organizations
Impacts on
Patient / system risk, security, privacy, safety and quality

Topics and care settings

Topic
  • Information governance
  • International Standards

Review Information

Scope
ISO Interoperability Category: Technical ISO Area / Topic: Security, Safety, and Privacy;
Registration status

ISO - standard

Registration authority

ISO

More information

This International Standard gives guidelines for organizational information security standards and information security management practices including the selection, implementation and management of controls taking into consideration the organization’s information security risk environment(s). This International Standard defines guidelines to support the interpretation and implementation in health informatics of ISO/IEC 27002 and is a companion to that International Standard.

Page last updated: 01 December 2025