ILNAS 107:2020 (E)
Introduction
ILNAS 107:2020 - Preview only Copy via ILNAS e-Shop
Considering the increasing importance of digitization and the evolution of digital services supporting quality
management and management of processes in laboratories, the objectives of this document on information
security requirements in laboratories are:
to offer a more in-depth interpretation of the requirements formulated in the two standards ILNAS-EN
ISO 15189:2012 and ILNAS-EN ISO/IEC 17025:2017;
to propose recommendations for the implementation of adequate information security controls in
laboratories, adapted to their needs;
to focus on the risk-based approach to information security adopted by laboratories;
to provide more recommendations to the assessors of the Office Luxembourgeois d'Accréditation et de
Surveillance (OLAS) for assessing information security aspects in the context of an accreditation
assessment.
This document may help laboratories to comply with Article 32 "Security of processing" of Regulation (EU)
2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons
with regard to the processing of personal data and on the free movement of such data, and repealing Directive
95/46/EC (General Data Protection Regulation) (GDPR) [1].
This document can serve as good practice for public sector laboratories to comply with the amended Law of 14
September 2018 on a transparent and open administration [2].
4