Health software and health IT systems safety, effectiveness and security — Part 5-1: Security — Activities in the product life cycle
Health software and health IT systems safety, effectiveness and security — Part 5-1: Security — Activities in the product life cycle
This document defines the LIFE CYCLE requirements for development and maintenance of HEALTH SOFTWARE needed to support conformance to IEC 62443-4-1 – taking the specific needs for HEALTH SOFTWARE into account. The set of PROCESSES, ACTIVITIES, and TASKS described in this document establishes a common framework for secure HEALTH SOFTWARE LIFE CYCLE PROCESSES. The purpose is to increase the CYBERSECURITY of HEALTH SOFTWARE by establishing certain ACTIVITIES and TASKS in the HEALTH SOFTWARE LIFE CYCLE PROCESSES and also by increasing the SECURITY of SOFTWARE LIFE CYCLE PROCESSES themselves. It is important to maintain an appropriate balance of the key properties SAFETY, effectiveness and SECURITY as discussed in ISO 81001-1. This document excludes specification of ACCOMPANYING DOCUMENTATION contents.
IEC 81001-5-1:2021 (Health software and health IT systems - Part 5-1) defines life‑cycle requirements to increase the cybersecurity of health software and health IT systems. Intended to support conformance with IEC 62443-4-1, the standard prescribes a common framework of processes, activities and tasks across the health software life cycle. It emphasizes maintaining an appropriate balance among safety, effectiveness and security (as discussed in ISO 81001-1) and focuses on activities in development, release, maintenance and decommissioning. The document does not prescribe the exact contents of accompanying documentation.
Стандарты, упомянутые в описании
Keywords: IEC 81001-5-1, health software lifecycle, health IT cybersecurity, secure software development lifecycle, threat modelling, vulnerability management, IEC 62443, medical device security.