首页> 外文会议>IEEE International Conference on Software Architecture Companion >Continuous security patch delivery and risk management for medical devices
【24h】

Continuous security patch delivery and risk management for medical devices

机译:医疗设备的持续安全补丁交付和风险管理

获取原文

摘要

This paper is a case study describing our practical experience in the area of cybersecurity for medical devices. We describe how Siemens Healthineers uses a continuous security patch delivery model in a regulated market across 15+ business lines which cover our huge portfolio of imaging modalities, laboratory and point-of-care instruments. The case study addresses how we have implemented a continuous security patch delivery strategy. The strategy embraces a systematic way of product-specific vulnerability evaluations based on design knowledge and operator-oriented risk communication which are the novel aspects of this work. Focusing on the ‘real’ cybersecurity risks in the early phase of the continuous delivery process leads to reduced cost for post-market management of medical devices. The paper also describes how this dynamic, continuous and highly automated approach is intended to satisfy the current and future demands of the National Telecommunications and Information Administration (NTIA) the existing FDA post-market guidance and the upcoming revision of the FDA pre-market guidance on cybersecurity to provide operators with a “software bill of material” (SBOM).
机译:本文是一个案例研究,描述了我们在医疗设备网络安全领域的实践经验。我们将介绍Siemens Healthineers如何在15多个业务领域的受监管市场中使用连续安全补丁交付模型,这些业务领域涵盖了我们庞大的成像设备,实验室和即时医疗器械产品组合。该案例研究解决了我们如何实施连续的安全补丁交付策略。该策略采用了基于设计知识和面向操作员的风险沟通的针对特定产品的漏洞评估的系统方法,这是这项工作的新颖之处。在持续交付过程的早期阶段专注于“实际”网络安全风险可以降低医疗设备上市后管理的成本。本文还描述了这种动态,连续和高度自动化的方法是如何满足美国国家电信和信息管理局(NTIA)当前和未来的要求,现有的FDA上市后指南以及即将修订的FDA上市前指南。网络安全方面的问题,为运营商提供“软件物料清单”(SBOM)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号