首页> 外文会议>IEEE International Conference on Software Architecture Companion >Continuous security patch delivery and risk management for medical devices
【24h】

Continuous security patch delivery and risk management for medical devices

机译:医疗设备的连续安全补丁交付和风险管理

获取原文

摘要

This paper is a case study describing our practical experience in the area of cybersecurity for medical devices. We describe how Siemens Healthineers uses a continuous security patch delivery model in a regulated market across 15+ business lines which cover our huge portfolio of imaging modalities, laboratory and point-of-care instruments. The case study addresses how we have implemented a continuous security patch delivery strategy. The strategy embraces a systematic way of product-specific vulnerability evaluations based on design knowledge and operator-oriented risk communication which are the novel aspects of this work. Focusing on the ‘real’ cybersecurity risks in the early phase of the continuous delivery process leads to reduced cost for post-market management of medical devices. The paper also describes how this dynamic, continuous and highly automated approach is intended to satisfy the current and future demands of the National Telecommunications and Information Administration (NTIA) the existing FDA post-market guidance and the upcoming revision of the FDA pre-market guidance on cybersecurity to provide operators with a “software bill of material” (SBOM).
机译:本文是一个案例研究,描述了我们在医疗设备的网络安全领域的实践经验。我们描述了西门子发电机如何在一条跨越15遍的业务线上的监管市场中使用连续安全补丁交付模型,该产品涵盖了我们庞大的成像模型,实验室和护理仪器的巨大组合。案例研究解决了我们如何实施连续的安全补丁传递策略。该策略基于设计知识和经营者为导向的风险沟通,拥有产品特定漏洞评估的系统方式,这是这项工作的新颖方面。专注于持续交付过程的早期阶段的“真实”网络安全风险导致医疗器械后市场管理的成本降低。本文还描述了这种动态,持续和高度自动化的方法旨在满足国家电信和信息管理局(NTIA)现有FDA后市场指导和即将到来的FDA预先市场预告关于网络安全,为运营商提供“软件材料账单”(SBOM)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号