Showing posts with label medical devices. Show all posts
Showing posts with label medical devices. Show all posts

Sunday, March 24, 2024

New International Medical Device Standard

 With standards, regulations, statutes, etc., many feel this is a speedbump for their product. In the interest of the field, industry patient safety, and security these are a great idea. Without these in place, medical device cybersecurity could become like the Weld West with every entity doing their own thing, not following any guidance.

The FDA has recognized three new standards focused on medical device software security. These cover the total product lifecycle of medical device cybersecurity, data logging, software use, and reasonable software testing.

The first noted standard was ANSI/AAMI 2700-2-1. This standard is focused on medical device software’s safe usage in the integrated clinical environment (ICE). The specific usage is for data loggers to appropriately collect data in these systems. This includes the recording, data, storage, and playback for the data. The data usage would be for safety, quality assurance, and forensic analysis.

The second standard was ANSI/AAMI SW96:2023, which provides guidance on methods to manage security risks. Medical devices present a unique security risk. The standard addresses several security areas to identify threats and vulnerabilities and the controls to put in place to mitigate these.

Lastly ISO IEC IEEE 29119-1 provides guidance on germane topics in the field including software.

These standards provide additional guidance and a framework to further the safety and security for the products. By adding these into our security tools, the attack surface is decreasing, and potential attacks are mitigated.

 Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


Wednesday, February 14, 2024

SBoMs

 

SBoMs (Software Bill of Materials) are an inventory of the software in the product or service. This lists the software packages, versions, and other data. This is a useful tool in that you have a current list of software components. This can be used for checking for vulnerabilities and new attacks, along with verifying client questions. There have been new attacks and vendors have called to verify if the affected components are included in the product or service purchased.

In addition, the FDA has published their new mandate requiring medical device manufacturers to provide the SBoM. The FDA mandate is clear and allows manufactures to produce this. The new standard for the data presentation is ready and clear. 


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) 


 charles.parker@mielcybersecurity.net 810-701-5511



Tuesday, January 9, 2024

New Frontiers

 

Over the years there have been differing targets, moving from the enterprise side, to vehicles, satellites, shipping, aeronautics, and others. A significant new industry focus are medical devices. What brings this to the forefront of our attention is the criticality of the devices. These assist with our lives and living. The insulin pump helps patients with their blood sugar and notifies the patient when this is too high or low and provides insulin through the day. Neurotransmitters help patients deal with their pain. Defibrillators help with regulating heartbeats.

While these clearly are a benefit for the patients, these require cybersecurity to be applied. Without a thorough architecture and pentest to ensure the vulnerabilities have been mitigated, there are substantial liabilities. To validate this, you simply need to read through the FDA notices. Without fully addressing the product’s cybersecurity, the manufacturer is missing vital points which are required.

Thank you.


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture

Red Team Pentesting | HW & SW BoMs | CBoM | 

Vulnerability Management | Tabletop Exercises (TTX) | 

Embedded Systems Architecture | Threat Intelligence | 

TARA (Threat Assessment and Remediation Analysis) 


Disabled Veteran Owned and Operated