Continuous security patch delivery and risk management for medical devices

被引:2
作者
Von Stockhausen, Hans-Martin [1 ]
Rose, Marc [2 ]
机构
[1] Siemens Healthineers, Prod & Solut Secur, Erlangen, Germany
[2] Siemens Healthineers, Cybersecur, Erlangen, Germany
来源
2020 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ARCHITECTURE COMPANION (ICSA-C 2020) | 2020年
关键词
cybersecurity; security development lifecycle vulnerability; vulnerability handling; product-specific risk management; continuous security patch delivery; medical device post-market;
D O I
10.1109/ICSA-C50368.2020.00043
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This paper is a case study describing our practical experience in the area of cybersecurity for medical devices. We describe how Siemens Healthineers uses a continuous security patch delivery model in a regulated market across 15+ business lines which cover our huge portfolio of imaging modalities, laboratory and point-of-care instruments. The case study addresses how we have implemented a continuous security patch delivery strategy. The strategy embraces a systematic way of product-specific vulnerability evaluations based on design knowledge and operator-oriented risk communication which are the novel aspects of this work. Focusing on the 'real' cybersecurity risks in the early phase of the continuous delivery process leads to reduced cost for post-market management of medical devices. The paper also describes how this dynamic, continuous and highly automated approach is intended to satisfy the current and future demands of the National Telecommunications and Information Administration (NTIA) the existing FDA post-market guidance and the upcoming revision of the FDA pre-market guidance on cybersecurity to provide operators with a "software hill of material" (SBOM).
引用
收藏
页码:204 / 209
页数:6
相关论文
共 12 条
[1]  
[Anonymous], 2016, Postmarket management of cybersecurity in medical devices
[2]  
[Anonymous], 8000112010 IEC
[3]  
Center for Devices and Radiological Health, 2018, Content of premarket submissions for management of cybersecurity in medical devices
[4]   Data breach remediation efforts and their implications for hospital quality [J].
Choi, Sung J. ;
Johnson, M. Eric ;
Lehmann, Christoph U. .
HEALTH SERVICES RESEARCH, 2019, 54 (05) :971-980
[5]  
FDA, 2014, Content of Premarket Submissions for Management of Cybersecurity in Medical Devices Guidance for Industry and Food and Drug Administration Staff
[6]  
Food and Drug Administration, TITL 21 FOOD DRUGS F
[7]  
Friedman Allan, 2019, MOVING MORE TRANSPAR
[8]  
Hegendorfer F., 2018, Patent No. [EP3358483A1, 3358483]
[9]  
Microsoft, SEC DEV LIF WEB PORT
[10]  
National Telecommunications and Information Administration, 2019, SOFTW COMP TRANSP HE