Well, there are plenty provisions under the security chapter, funnily enough now that I look at it again (been long time) it seems both 'accountability' (tracking every media in and out) and 'protection from malicious software' are not listed as required. duh.
The emergency mode operation plan is however listed as required, and this place was basically shut for a week.
I remembered it being more stringent that what it really is.