A Method of Assessing Data Quality in Publicly Available Cybersecurity Data Sources for Use in Medical Device Cybersecurity Risk Management

被引:0
作者
Curran, Barry [1 ]
Egan, James [1 ]
机构
[1] South East Technol Univ, Dept Comp, Carlow, Ireland
来源
2023 CYBER RESEARCH CONFERENCE-IRELAND, CYBER-RCI 2023 | 2023年
关键词
medical devices; healthcare; 4.0; cybersecurity; patient safety; harm; risk; quantitative; data quality;
D O I
10.1109/Cyber-RCI59474.2023.10671424
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This paper addresses the growing risk of cybersecurity threats in the healthcare industry, fueled by Healthcare 4.0 and the proliferation of connected medical devices. Existing risk methodologies primarily focus on identifying risk after a product has been designed, which poses challenges for implementing security by design early in the development lifecycle. Inadequate security measures in medical devices not only pose a risk of patient data exposure but also the potential for patient harm, including serious injury or death. The healthcare industry faces resource and expertise challenges in executing risk analysis early and ensuring that product security protects patient safety. To address these issues, this paper has sought the opinions of industry professionals to find out what are the main issues that were affecting the development of early product risk assessments and proposes a Risk Intelligence Framework that utilizes publicly available data sources to support the assessment.
引用
收藏
页数:9
相关论文
共 67 条
[1]  
Abu Ali Khadija, 2021, 2021 International Conference on Information Technology (ICIT), P695, DOI 10.1109/ICIT52682.2021.9491669
[2]  
Akami, 2021, Akami. defenses for a diabetes therapy system, P150
[3]  
[Anonymous], 2022, Global Food Security Index 2022
[4]  
[Anonymous], 2022, FORTINET
[5]  
[Anonymous], 2021, Conti Cyber Attack on the HSE: Independent Post-Incident Review
[6]  
[Anonymous], 2023, CYB REP
[7]  
[Anonymous], 2022, State of cybersecurity 2022
[8]  
[Anonymous], 2016, 2016 COST CYBER CRIM
[9]  
[Anonymous], 2019, [No title captured]
[10]  
[Anonymous], 2022, Global incident response threat report