医疗设备的持续安全补丁交付和风险管理

H. V. Stockhausen, M. Rose
{"title":"医疗设备的持续安全补丁交付和风险管理","authors":"H. V. Stockhausen, M. Rose","doi":"10.1109/ICSA-C50368.2020.00043","DOIUrl":null,"url":null,"abstract":"This paper is a case study describing our practical experience in the area of cybersecurity for medical devices. We describe how Siemens Healthineers uses a continuous security patch delivery model in a regulated market across 15+ business lines which cover our huge portfolio of imaging modalities, laboratory and point-of-care instruments. The case study addresses how we have implemented a continuous security patch delivery strategy. The strategy embraces a systematic way of product-specific vulnerability evaluations based on design knowledge and operator-oriented risk communication which are the novel aspects of this work. Focusing on the ‘real’ cybersecurity risks in the early phase of the continuous delivery process leads to reduced cost for post-market management of medical devices. The paper also describes how this dynamic, continuous and highly automated approach is intended to satisfy the current and future demands of the National Telecommunications and Information Administration (NTIA) the existing FDA post-market guidance and the upcoming revision of the FDA pre-market guidance on cybersecurity to provide operators with a “software bill of material” (SBOM).","PeriodicalId":202587,"journal":{"name":"2020 IEEE International Conference on Software Architecture Companion (ICSA-C)","volume":"531 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-03-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Continuous security patch delivery and risk management for medical devices\",\"authors\":\"H. V. Stockhausen, M. Rose\",\"doi\":\"10.1109/ICSA-C50368.2020.00043\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper is a case study describing our practical experience in the area of cybersecurity for medical devices. We describe how Siemens Healthineers uses a continuous security patch delivery model in a regulated market across 15+ business lines which cover our huge portfolio of imaging modalities, laboratory and point-of-care instruments. The case study addresses how we have implemented a continuous security patch delivery strategy. The strategy embraces a systematic way of product-specific vulnerability evaluations based on design knowledge and operator-oriented risk communication which are the novel aspects of this work. Focusing on the ‘real’ cybersecurity risks in the early phase of the continuous delivery process leads to reduced cost for post-market management of medical devices. The paper also describes how this dynamic, continuous and highly automated approach is intended to satisfy the current and future demands of the National Telecommunications and Information Administration (NTIA) the existing FDA post-market guidance and the upcoming revision of the FDA pre-market guidance on cybersecurity to provide operators with a “software bill of material” (SBOM).\",\"PeriodicalId\":202587,\"journal\":{\"name\":\"2020 IEEE International Conference on Software Architecture Companion (ICSA-C)\",\"volume\":\"531 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-03-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 IEEE International Conference on Software Architecture Companion (ICSA-C)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICSA-C50368.2020.00043\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE International Conference on Software Architecture Companion (ICSA-C)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSA-C50368.2020.00043","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

本文是一个案例研究,描述了我们在医疗设备网络安全领域的实践经验。我们介绍了西门子健康工程师如何在15多个业务线的监管市场中使用持续的安全补丁交付模式,这些业务线涵盖了我们庞大的成像模式、实验室和护理点仪器产品组合。案例研究讨论了我们如何实现持续的安全补丁交付策略。该策略包含了一种基于设计知识和面向操作人员的风险沟通的系统的特定产品脆弱性评估方法,这是本工作的新颖方面。在持续交付过程的早期阶段关注“真正的”网络安全风险,可以降低医疗器械上市后管理的成本。该文件还描述了这种动态、持续和高度自动化的方法如何满足国家电信和信息管理局(NTIA)现有的FDA上市后指南和即将修订的FDA上市前网络安全指南的当前和未来需求,以向运营商提供“软件材料清单”(SBOM)。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Continuous security patch delivery and risk management for medical devices
This paper is a case study describing our practical experience in the area of cybersecurity for medical devices. We describe how Siemens Healthineers uses a continuous security patch delivery model in a regulated market across 15+ business lines which cover our huge portfolio of imaging modalities, laboratory and point-of-care instruments. The case study addresses how we have implemented a continuous security patch delivery strategy. The strategy embraces a systematic way of product-specific vulnerability evaluations based on design knowledge and operator-oriented risk communication which are the novel aspects of this work. Focusing on the ‘real’ cybersecurity risks in the early phase of the continuous delivery process leads to reduced cost for post-market management of medical devices. The paper also describes how this dynamic, continuous and highly automated approach is intended to satisfy the current and future demands of the National Telecommunications and Information Administration (NTIA) the existing FDA post-market guidance and the upcoming revision of the FDA pre-market guidance on cybersecurity to provide operators with a “software bill of material” (SBOM).
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
ICSA-C 2020 Committees CompliancePal: A Tool for Supporting Practical Agile and Regulatory-Compliant Development of Medical Software On the Deployment of IoT Systems: An Industrial Survey PerfMinerArch - A Tool to Visualize and Analyze Performance Deviations Fostering Reuse by Integration: A Directed System of Systems Development Case
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1