Overall information security baseline. RONL implements BIO controls including access management (Keycloak RBAC), audit logging (PostgreSQL), and secure transmission (TLS everywhere).
NEN 7510
Information security in healthcare settings. Applied to the handling of citizen health-related data (zorgtoeslag eligibility).
AVG / GDPR
Data minimisation (BSN encrypted, not logged in plaintext), audit trail (7-year retention), purpose limitation (process variables scoped to the requesting service).
DigiD Norm
Authentication assurance levels (LoA) for citizen-facing services. RONL enforces LoA checks on sensitive endpoints via the loa JWT claim.
NCSC Beveiligingsrichtlijnen
Secure software development practices, dependency management, vulnerability disclosure.