IEC 81001-5-1:2021
Health software and health IT systems safety, effectiveness and security — Part 5-1: Security — Activities in the product life cycle
Health software and health IT systems safety, effectiveness and security — Part 5-1: Security — Activities in the product life cycle
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 114
- Дата публикации:
- 21 декабря 2021 г.
- Издание:
- IEC IS 81001 edition 1 version 1
- ICS:
- 35.080
This document defines the LIFE CYCLE requirements for development and maintenance of HEALTH SOFTWARE needed to support conformance to IEC 62443-4-1 – taking the specific needs for HEALTH SOFTWARE into account. The set of PROCESSES, ACTIVITIES, and TASKS described in this document establishes a common framework for secure HEALTH SOFTWARE LIFE CYCLE PROCESSES. The purpose is to increase the CYBERSECURITY of HEALTH SOFTWARE by establishing certain ACTIVITIES and TASKS in the HEALTH SOFTWARE LIFE CYCLE PROCESSES and also by increasing the SECURITY of SOFTWARE LIFE CYCLE PROCESSES themselves. It is important to maintain an appropriate balance of the key properties SAFETY, effectiveness and SECURITY as discussed in ISO 81001-1. This document excludes specification of ACCOMPANYING DOCUMENTATION contents.
Abstract
Overview
IEC 81001-5-1:2021 (Health software and health IT systems - Part 5-1) defines life‑cycle requirements to increase the cybersecurity of health software and health IT systems. Intended to support conformance with IEC 62443-4-1, the standard prescribes a common framework of processes, activities and tasks across the health software life cycle. It emphasizes maintaining an appropriate balance among safety, effectiveness and security (as discussed in ISO 81001-1) and focuses on activities in development, release, maintenance and decommissioning. The document does not prescribe the exact contents of accompanying documentation.
Key topics and technical requirements
- Secure life‑cycle processes: Establishes required activities across planning, development, integration, testing, release and maintenance phases of health software.
- Quality management & responsibilities: Calls for defined quality systems, explicit assignment of security responsibilities, and continuous improvement.
- Security risk management: Defines processes to identify vulnerabilities, assess threats, estimate and control security risks and monitor controls.
- Software classification & supplier management: Addresses classification of software items (e.g., maintained vs supported), and management of third‑party components.
- Secure design and implementation: Covers architectural defence‑in‑depth, secure design best practices and secure coding standards.
- Verification & testing: Requires security‑focused verification, vulnerability testing, threat mitigation testing and guidance on penetration testing and tester independence.
- Release & integrity controls: Covers release documentation, file integrity, private key controls and criteria for resolving security findings before release.
- Maintenance & vulnerability handling: Establishes maintenance planning, timely security updates, verification of updates and processes for receiving and addressing vulnerability reports.
- Configuration and problem resolution: Includes software configuration management and structured problem/incident resolution processes.
- Threat modelling & guidance: Informative annexes provide methods (e.g., STRIDE, attack‑defense concepts), implementation guidance and rationale.
Applications - who uses this standard
- Medical device manufacturers and health IT developers implementing a secure software development lifecycle (SSDLC).
- Cybersecurity, quality and regulatory teams preparing evidence for conformity to IEC 62443 or national medical device regulations.
- Clinical engineers, integrators and procurement officers who manage third‑party components and lifecycle patching.
- Test labs and auditors assessing security testing, vulnerability management and release controls.
Related standards
- IEC 62443-4-1 (industrial product secure development lifecycle) - alignment and conformance target.
- IEC 62304 (software lifecycle processes for medical device software) - lifecycle and safety overlap.
- ISO 81001-1 - foundational discussion on balancing safety, effectiveness and security.
Keywords: IEC 81001-5-1, health software lifecycle, health IT cybersecurity, secure software development lifecycle, threat modelling, vulnerability management, IEC 62443, medical device security.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- IEC 81001-5-1:2021
Похожие стандарты
Стандарты, упомянутые в описании
IEC 62443-4-1:2018
ДействующийSecurity for industrial automation and control systems - Part 4-1: Secure product development lifecycle requi…
Overview IEC 62443-4-1:2018, published by the International Electrotechnical Commission (IEC), establishes process requirements for the secure development of products used in industrial automation an…
ISO 81001-1:2021
ДействующийHealth software and health IT systems safety, effectiveness and security — Part 1: Principles and concepts
Overview ISO 81001-1:2021 - "Health software and health IT systems safety, effectiveness and security - Part 1: Principles and concepts" - defines the core principles, concepts, terms and definitions…
IEC 62443-3-3:2013
ДействующийIndustrial communication networks - Network and system security - Part 3-3: System security requirements and…
Overview IEC 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels - defines detailed technical requirements fo…