ILNAS 107:2020 (E)
Contents
Page
Foreword ..............................................................................................................................................................3
ILNAS 107:2020 - Preview only Copy via ILNAS e-Shop
Introduction .........................................................................................................................................................4
1
Scope of application ..............................................................................................................................5
2
Normative references ............................................................................................................................5
3
Terms and definitions ...........................................................................................................................5
4
Laboratory information security requirements ..................................................................................8
5
5.1
5.2
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
5.2.10
5.2.11
Objective and controls to implement information security in the laboratory .................................8
Objective .................................................................................................................................................8
Controls ............................................................................................................................................... 11
Availability and integrity of supporting assets documentation ..................................................... 11
Roles and responsibilities ................................................................................................................. 12
Change management ......................................................................................................................... 13
Access management .......................................................................................................................... 14
Backup of supporting assets ............................................................................................................ 15
Environmental conditions .................................................................................................................. 16
Storage of supporting assets ............................................................................................................ 17
Data protection .................................................................................................................................... 18
Transfer of information ...................................................................................................................... 18
Business continuity ............................................................................................................................ 19
Supplier compliance ........................................................................................................................... 20
Annex A (informative) Summary table of information security controls ................................................. 21
Annex B (informative) Summary table of all information security provisions/good practices ............. 22
Annex C (informative) Examples of generic risks to consider ................................................................. 23
Annex D (informative) Examples of assessment questions ..................................................................... 27
D.1
Questions related to the objective .................................................................................................... 27
D.2
Questions related to controls ............................................................................................................ 28
D.2.1 Availability and integrity of supporting assets documentation ..................................................... 28
D.2.2 Roles and responsibilities ................................................................................................................. 28
D.2.3 Change management ......................................................................................................................... 29
D.2.4 Access management .......................................................................................................................... 29
D.2.5 Backup of supporting assets ............................................................................................................ 30
D.2.6 Environmental conditions .................................................................................................................. 30
D.2.7 Storage of supporting assets ............................................................................................................ 31
D.2.8 Data protection .................................................................................................................................... 31
D.2.9 Transfer of information ...................................................................................................................... 32
D.2.10 Business continuity ............................................................................................................................ 32
D.2.11 Supplier compliance ........................................................................................................................... 33
Bibliography ..................................................................................................................................................... 34
2