An Overview of Cybersecurity Regulations and Standards for Medical Device Software

被引:0
|
作者
Lechner, Nadica Hrgarek [1 ]
机构
[1] MED EL Elektromed Gerate GmbH, Furstenweg 77, A-6020 Innsbruck, Austria
关键词
cybersecurity; FDA; information security; medical device software; security risk management;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper discusses current cybersecurity regulations and standards for medical device software set by government agencies and agencies developing industry and international standards such as the FDA (Food and Drug Administration), CFDA (China Food and Drug Administration), ISO (International Organization for Standardization), IEC (International Electrotechnical Commission), UL (Underwriters Laboratories), and others. The concepts described within this paper can be utilized by medical device manufacturers in order to establish a cybersecurity program as part of their quality management systems. In general, there are three complementary ways based on the NIST (National Institute of Standards and Technology) cybersecurity framework that can be used to remove gaps in the organization's cybersecurity. The first way focuses on designing software products that take cybersecurity into account (i.e., prevention). The second way is to perform security and penetration testing and to apply other cybersecurity controls to reduce attacks and vulnerabilities that could be exploited (i.e., detection). The third way emphasizes maintenance plan in case of a cyberattack (i.e., response and recovery).
引用
收藏
页码:237 / 249
页数:13
相关论文
共 50 条
  • [1] Controlling for Cybersecurity Risks of Medical Device Software
    Fu, Kevin
    Blum, James
    COMMUNICATIONS OF THE ACM, 2013, 56 (10) : 35 - 37
  • [2] Overview of Medical Device Regulations in Singapore and Thailand
    Khushbu D. Jain
    Sanjay B. Patil
    Biomedical Materials & Devices, 2025, 3 (1): : 259 - 276
  • [3] Developing Medical Device Software in compliance with regulations
    Zema, M.
    Rosati, S.
    Gioia, V.
    Knaflitz, M.
    Balestra, G.
    2015 37TH ANNUAL INTERNATIONAL CONFERENCE OF THE IEEE ENGINEERING IN MEDICINE AND BIOLOGY SOCIETY (EMBC), 2015, : 1331 - 1334
  • [4] An Overview of Global Professional Publications Related to Medical Device Cybersecurity
    Lechner, Nadica Hrgarek
    CENTRAL EUROPEAN CONFERENCE ON INFORMATION AND INTELLIGENT SYSTEMS (CECIIS 2020), 2020, : 219 - 230
  • [5] Automotive Cybersecurity Standards - Relation and Overview
    Schmittner, Christoph
    Macher, Georg
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2019, 2019, 11699 : 153 - 165
  • [6] The Creation and Certification of Software Cybersecurity Standards
    Axelrod, C. Warren
    2016 IEEE LONG ISLAND SYSTEMS, APPLICATIONS AND TECHNOLOGY CONFERENCE (LISAT), 2016,
  • [7] Achieving medical device EMC: The role of regulations, standards, guidelines and publications
    Silberberg, JL
    2001 IEEE EMC INTERNATIONAL SYMPOSIUM, VOLS 1 AND 2, 2001, : 1298 - 1303
  • [8] Self-Authentication in Medical Device Software An Approach To Include Cybersecurity In Legacy Medical Devices
    Jagannathan, Srinivasan
    Sorini, Adam
    2016 IEEE Symposium on Product Compliance Engineering (ISPCE), 2016,
  • [9] Cybersecurity in PACS and Medical Imaging: an Overview
    Eichelberg, Marco
    Kleber, Klaus
    Kaemmerer, Marc
    JOURNAL OF DIGITAL IMAGING, 2020, 33 (06) : 1527 - 1542
  • [10] Cybersecurity in PACS and Medical Imaging: an Overview
    Marco Eichelberg
    Klaus Kleber
    Marc Kämmerer
    Journal of Digital Imaging, 2020, 33 : 1527 - 1542