ILNAS 107:2020 (E) Contents Page Foreword ..............................................................................................................................................................3 ILNAS 107:2020 - Preview only Copy via ILNAS e-Shop Introduction .........................................................................................................................................................4 1 Scope of application ..............................................................................................................................5 2 Normative references ............................................................................................................................5 3 Terms and definitions ...........................................................................................................................5 4 Laboratory information security requirements ..................................................................................8 5 5.1 5.2 5.2.1 5.2.2 5.2.3 5.2.4 5.2.5 5.2.6 5.2.7 5.2.8 5.2.9 5.2.10 5.2.11 Objective and controls to implement information security in the laboratory .................................8 Objective .................................................................................................................................................8 Controls ............................................................................................................................................... 11 Availability and integrity of supporting assets documentation ..................................................... 11 Roles and responsibilities ................................................................................................................. 12 Change management ......................................................................................................................... 13 Access management .......................................................................................................................... 14 Backup of supporting assets ............................................................................................................ 15 Environmental conditions .................................................................................................................. 16 Storage of supporting assets ............................................................................................................ 17 Data protection .................................................................................................................................... 18 Transfer of information ...................................................................................................................... 18 Business continuity ............................................................................................................................ 19 Supplier compliance ........................................................................................................................... 20 Annex A (informative) Summary table of information security controls ................................................. 21 Annex B (informative) Summary table of all information security provisions/good practices ............. 22 Annex C (informative) Examples of generic risks to consider ................................................................. 23 Annex D (informative) Examples of assessment questions ..................................................................... 27 D.1 Questions related to the objective .................................................................................................... 27 D.2 Questions related to controls ............................................................................................................ 28 D.2.1 Availability and integrity of supporting assets documentation ..................................................... 28 D.2.2 Roles and responsibilities ................................................................................................................. 28 D.2.3 Change management ......................................................................................................................... 29 D.2.4 Access management .......................................................................................................................... 29 D.2.5 Backup of supporting assets ............................................................................................................ 30 D.2.6 Environmental conditions .................................................................................................................. 30 D.2.7 Storage of supporting assets ............................................................................................................ 31 D.2.8 Data protection .................................................................................................................................... 31 D.2.9 Transfer of information ...................................................................................................................... 32 D.2.10 Business continuity ............................................................................................................................ 32 D.2.11 Supplier compliance ........................................................................................................................... 33 Bibliography ..................................................................................................................................................... 34 2

Select target paragraph3