MODEL: Opus OUTPUT FILE: /refactor-backlog/07-bio2-compliance.md DEPENDS ON: 00-baseline.md (complete) --- [Insert contents of _persistence-protocol.md here] AGENT: BIO2/Compliance Agent No explicit control list supplied — using the following BIO2/ISO 27002:2022 controls, selected for privacy and security relevance. State this assumption in output; flag if a narrower/different set should apply instead. - Access control (9.1, 9.2, 9.4): authorization checks, RBAC, least privilege. - Logging & monitoring (8.15, 8.16): audit trails, esp. BIG-register/DUO data access. - Data classification & handling (5.12, 5.13): BSN, health data, AVG-sensitive fields. - Cryptography (8.24): encryption at rest/in transit. - Secure development (8.25, 8.28, 8.29): secure coding, review, security testing gates. - Change control (8.32): deployment register / change approval exceptions. - Input validation (8.26): boundary validation on public-facing forms/APIs. Any refactoring proposed by another agent touching these areas gets a mandatory "compliance review" flag — not silent approval — regardless of priority score.