Presentation is loading. Please wait.

Presentation is loading. Please wait.

MEM Cybersecurity Working Group Update to PCD Technical Committee

Similar presentations


Presentation on theme: "MEM Cybersecurity Working Group Update to PCD Technical Committee"— Presentation transcript:

1 MEM Cybersecurity Working Group Update to PCD Technical Committee
Sept. 14, 2016

2 IHE PCD MEM Cybersecurity Working Group - Mission:
Develop and provide cybersecurity guidance to the larger patient care and medical device industries: technology best practices, recommended policies & procedures, regulatory compliance, education and enablement, and sharing across stakeholders. This will build on and use existing healthcare and non-healthcare security frameworks and standards (e.g. IHE ITI but also non-IHE) and will consolidate and apply them to the unique medical device use cases. Current Cybersecurity Working Group Members: Philips, Draeger, Smiths Medical, Symantec, BBraun, individual members Existing Relationships: IHE ITI, IHE PCD MEM DMC/LS Group MDISS (MOU in place) Shared members: AAMI Device Security WG (TIR 57), Advamed, NH-ISAC, ISO TC215 JWG 7 Working relationships: FDA, US-CERT, DHS, ECRI Past Projects (completed): Cybersecurity Awareness WP (2011) Cybersecurity Best Practices WP (2015) ** Medical Device Patching WP (2015, in cooperation with MDISS) ** ** should be updated to reflect recent FDA Cybersecurity Guidance

3 Medical Device Cybersecurity Ecosystem Map – DRAFT (2016 08 22)
Security Community Threat, Incident, & Vulnerability Intelligence Security Research Security Frameworks & Best Practices Regulations, Standards, Frameworks Government & Local Requirements Compliance Security Privacy Information Systems Security Risk Analysis & Management Security Defense & Incident Response Auditing & Reporting Medical Device Market Approval Manufacturing Quality Systems (GMP) Hazard Analysis Certification & Assurance Security Baseline Certification Standards Testing & Certification Auditing & Reporting Integration & Maintenance Vulnerability Sharing & Mgmt. Incident Reporting Life Cycle Maintenance (patching, etc.) Integration Architecture Manufacturer HDO Objective: Safety, Operational reliability, protect IP Policies & Procedures, incl. Quality System Contract Mgmt / Agreements / Supply Chain Software & Security Design Best Practices Asset Mgmt. Risk Mgmt. (Hazard Analysis, etc.) Risk Mitigation Threat & Vulnerability Sharing Incident Response & Reporting Documentation Secure Remote Access Objective: Minimize C-I-A Risk to Safety, Security, Privacy Policies & Procedures Contract Mgmt / Agreements / Procurement Asset, Configuration & Lifecycle (Change) Mgmt. Risk Mgmt. (HDO level) Risk Mitigation Incident Response & Reporting Device EOL Training & Education

4 IHE PCD MEM Cybersec WG - Proposal
Update 2015 WPs to reflect FDA Postmarket Security Guidance (upon final release) Complete Ecosystem map: Review internally (IHE) and externally (public review) Produce & publish final Identify already active stakeholders or existing standards/ frameworks for each topic areas Identify gaps Propose how to address gaps Approach (whitepaper, specifications, standards, etc.) Suggested owner (IHE or outside) This approach is in line with IHE’s mission to provide guidance to the industry on complex and multi-stakeholder problems.

5 Obstacles: Bench strength – small group.
Manufacturers only – how can we get better contribution from (and attract) HDO’s? US-focus – lack of international exposure and visibility. Official Mission and Tasks – how to proceed? This proposal for review and approval / turn proposal into a official project?


Download ppt "MEM Cybersecurity Working Group Update to PCD Technical Committee"

Similar presentations


Ads by Google