Summary

ISO 27001 is the international standard for information security. NEN 7510 is the Dutch standard for information security in healthcare, aimed specifically at the healthcare sector. It is based on ISO 27001 but adds further requirements for protecting health data.

ISO 27001: The international standard

ISO 27001 is an internationally recognised standard for establishing, implementing and maintaining an Information Security Management System (ISMS). The standard applies to all types of organisation, regardless of sector or size.

The current version, ISO 27001:2022, contains 93 controls divided across 4 categories: organisational, people, physical and technological. Organisations decide for themselves which controls apply, based on their risk assessment.

NEN 7510: Specific to healthcare

NEN 7510 is the Dutch standard for information security in healthcare. The standard is based on ISO 27001, but contains additional requirements that are specifically relevant to protecting patient data and health data.

NEN 7510 is often used in combination with NEN 7512 (basis of trust for data exchange) and NEN 7513 (logging of access to patient data).

Comparison

Aspect ISO 27001 NEN 7510
Scope All sectors Healthcare
Origin International (ISO) Dutch (NEN)
Basis Standalone standard Based on ISO 27001
Certification Internationally recognised Recognised in the Netherlands
Patient data No specific requirements Extensive requirements
Mandatory? Voluntary (unless required by contract) Mandatory in healthcare

When do you choose which standard?

Choose ISO 27001 if:

  • You do not work in the healthcare sector
  • You need international recognition
  • Customers or partners require ISO 27001
  • You want a broad information security system

Choose NEN 7510 if:

  • You work in healthcare
  • You work with patient data or health data
  • It is a legal requirement for your organisation
  • You are a supplier to the healthcare sector

Tip: combining both standards

Do you work in healthcare and would you also like international recognition? In that case you can combine both standards. NEN 7510 is based on ISO 27001, so much of the work overlaps. ComplianceGuard supports both standards in one integrated system.

Benefits of an integrated approach

By managing ISO 27001 and NEN 7510 in one system:

ComplianceGuard supports both standards

With ComplianceGuard you manage ISO 27001 and NEN 7510 compliance in one integrated system. Including predefined templates, checklists and a clear dashboard.

Request a demo →

More articles