ILNAS 107:2020 (E) Introduction ILNAS 107:2020 - Preview only Copy via ILNAS e-Shop Considering the increasing importance of digitization and the evolution of digital services supporting quality management and management of processes in laboratories, the objectives of this document on information security requirements in laboratories are:  to offer a more in-depth interpretation of the requirements formulated in the two standards ILNAS-EN ISO 15189:2012 and ILNAS-EN ISO/IEC 17025:2017;  to propose recommendations for the implementation of adequate information security controls in laboratories, adapted to their needs;  to focus on the risk-based approach to information security adopted by laboratories;  to provide more recommendations to the assessors of the Office Luxembourgeois d'Accréditation et de Surveillance (OLAS) for assessing information security aspects in the context of an accreditation assessment. This document may help laboratories to comply with Article 32 "Security of processing" of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (GDPR) [1]. This document can serve as good practice for public sector laboratories to comply with the amended Law of 14 September 2018 on a transparent and open administration [2]. 4

Select target paragraph3