Development of a Process Assessment Model for Assessing Medical IT Networks against IEC 80001-1

被引:0
作者
MacMahon, Silvana Togneri [1 ]
McCaffery, Fergal [1 ]
Eagles, Sherman [2 ]
Keenan, Frank [1 ]
Lepmets, Marion [3 ]
Renault, Alain [3 ]
机构
[1] Dundalk Inst Technol & Lero, Regulated Software Res Grp, Dept Comp & Math, Dundalk, Louth, Ireland
[2] SoftwareCPR, St Paul, MN 55114 USA
[3] Public Res Ctr Henri Tudor, Luxembourg, Luxembourg
来源
SOFTWARE PROCESS IMPROVEMENT AND CAPABILITY DETERMINATION | 2012年 / 290卷
基金
爱尔兰科学基金会;
关键词
IEC; 80001-1; ISO/IEC 15504-Process Assessment; Service Management; ISO/IEC; 20000-1; TIPA; ITIL;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Increasingly medical devices are being designed to allow them to exchange information over an IT network. However incorporating a medical device into an IT network can introduce risks which can impact the safety, effectiveness and security of the medical device. Medical devices are stringently tested according to regulation during the design and manufacture process. However until the introduction of IEC 80001-1: Application of Risk Management for IT-Networks incorporating Medical Devices, no standard addressed the risks of incorporating a medical device into an IT network. In order to perform an assessment (which is compliant with ISO/IEC 15504-2) of an IT network against IEC 80001-1, a Process Assessment Model is required. Based on the relationship between IEC 80001-1 and ISO/EEC 20000-1, this paper examines how the TIPA transformation process developed by Public Research Centre Henri Tudor was used to develop a process assessment model (TIPA PAM) for ISO/IEC 20000-1. It also examines how a process assessment model can be developed following that transformation process to assess Medical IT networks against IEC 80001-1.
引用
收藏
页码:148 / +
页数:3
相关论文
共 15 条
  • [1] [Anonymous], 155042 ISOIEC
  • [2] [Anonymous], 155045 ISOIEC
  • [3] Barafort B, 2002, LECT NOTES COMPUT SC, V2559, P314
  • [4] Barafort B, 2009, BEST PRACTICE, V217
  • [5] Barafort B., 2008, SPICE 2008 NUR GERM
  • [6] Cartlidge A, 2007, INTRO OVERVIEW ITILV
  • [7] Cooper T, 2011, GETTING STARTED IEC, P76
  • [8] Dugmore J., 2008, ITILV3 ISO IEC 20000
  • [9] IEC, 2010, IEC 80001-1-application of risk management for IT-networks incorporating medical devices-part 1: roles, responsibilities and activities
  • [10] International Organization for Standardization, 2007, 149712007 ISO