EN ISO/IEEE 11073-40101:2022 PDF
Health informatics - Device interoperability - Part 40101: Foundational - Cybersecurity - Processes for vulnerability assessment (ISO/IEEE 11073-40101:2022)
Health informatics - Device interoperability - Part 40101: Foundational - Cybersecurity - Processes for vulnerability assessment (ISO/IEEE 11073-40101:2022)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 55
- Дата публикации:
- 30 марта 2022 г.
- Издание:
- CEN EN 11073 edition 1 version 1
- ICS:
- 35.240.80
Within the context of secure plug-and-play interoperability, cybersecurity is the process and capability of preventing unauthorized access or modification, misuse, denial of use, or the unauthorized use of information that is stored on, accessed from, or transferred to and from a PHD/PoCD. The process part of cybersecurity is risk analysis of use cases specific to a PHD/PoCD. For PHDs/PoCDs, this standard defines an iterative, systematic, scalable, and auditable approach to identification of cybersecurity vulnerabilities and estimation of risk. This iterative vulnerability assessment uses the Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE) classification scheme and the embedded Common Vulnerability Scoring System (eCVSS). The assessment includes system context, system decomposition, pre-mitigation scoring, mitigation, and post-mitigation scoring and iterates until the remaining vulnerabilities are reduced to an acceptable level of risk.
Abstract
Overview
EN ISO/IEEE 11073-40101:2022 defines a foundational, repeatable process for cybersecurity vulnerability assessment specifically for Personal Health Devices (PHDs) and Point‑of‑Care Devices (PoCDs). Published and adopted by CEN in 2022, this standard frames cybersecurity as both a capability and a process (including risk analysis of use cases) within secure plug‑and‑play device interoperability. It prescribes an iterative, systematic, scalable and auditable method to identify vulnerabilities and estimate residual risk until risk is reduced to an acceptable level.
Key Topics
- Scope and context: Addresses cybersecurity in the context of device interoperability and medical device communication (PHD/PoCD environments).
- Iterative assessment workflow: Defines steps including system context, system decomposition, pre‑mitigation scoring, mitigation design, and post‑mitigation scoring - repeated until acceptable risk is achieved.
- STRIDE threat classification: Uses Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege to categorize threats.
- Embedded CVSS (eCVSS): Integrates the Common Vulnerability Scoring System to quantify vulnerability severity for pre‑ and post‑mitigation scoring.
- Risk analysis of use cases: Emphasizes analyzing device use cases and operational context to prioritize vulnerabilities and mitigations.
- Auditability and scalability: Designed for traceable evidence of assessment decisions and suitable for devices ranging from simple PHDs to complex PoCD systems.
Applications
- Medical device manufacturers can use this standard to build cybersecurity into product development and maintainers can apply it during lifecycle updates.
- Healthcare IT and clinical engineers can apply the process to evaluate interoperability risks when integrating devices into hospital networks or home health ecosystems.
- Regulatory and compliance teams can use documented assessments (pre/post mitigation scores and iterations) as part of evidence for cybersecurity risk management and conformity.
- Security assessors and auditors use the STRIDE + eCVSS approach for consistent vulnerability classification and scoring across device types.
Who should use this standard
- Device manufacturers (PHD/PoCD vendors)
- Systems integrators and clinical engineers
- Cybersecurity assessors, QA and compliance teams in healthcare
- Regulatory bodies and procurement teams evaluating medical device security
Related Standards
- Part of the ISO/IEEE 11073 family for medical device interoperability; aligns with broader medical device cybersecurity and healthcare IT guidance. Use in conjunction with relevant regional regulatory guidance and risk‑management standards for medical devices.
Keywords: cybersecurity, vulnerability assessment, STRIDE, eCVSS, Personal Health Devices, Point‑of‑Care Devices, medical device interoperability, IEEE 11073, EN ISO/IEEE 11073-40101:2022.
Технические детали
- Технический комитет
- CEN/TC 251 - Medical informatics
- SKU
- EN ISO/IEEE 11073-40101:2022
Похожие стандарты
Другие стандарты EN
EN ISO 6599-1:2026
ДействующийPackaging - Conditioning for testing - Part 1: Paper sacks (ISO 6599-1:2026)
Overview EN ISO 6599-1:2026 - Packaging - Conditioning for testing - Part 1: Paper sacks is a key international standard developed by CEN and ISO. This document defines the conditioning atmospheres a…
EN ISO 4885:2026
ДействующийFerrous materials - Heat treatments - Vocabulary (ISO 4885:2026)
Overview EN ISO 4885:2026 - Ferrous Materials – Heat Treatments – Vocabulary is an international standard developed by CEN, aligning with ISO 4885:2026. This document provides comprehensive definitio…
EN ISO/IEC 29151:2026
ДействующийInformation security, cybersecurity and privacy protection - Controls, requirements, and guidance for persona…
Overview EN ISO/IEC 29151:2026 specifies controls, requirements, and guidance to ensure the proper protection of personally identifiable information (PII) within the fields of information security, c…
EN ISO 9693:2026
ДействующийDentistry - Compatibility testing for metal-ceramic and ceramic-ceramic systems (ISO 9693:2026)
Overview EN ISO 9693:2026 - Dentistry: Compatibility Testing for Metal-Ceramic and Ceramic-Ceramic Systems establishes internationally recognized requirements and test methods for evaluating the ther…
EN ISO 26082-1:2026
ДействующийLeather - Physical and mechanical test methods for the determination of soiling - Part 1: Rubbing (Martindale…
Overview EN ISO 26082-1:2026 is a European standard titled "Leather - Physical and mechanical test methods for the determination of soiling - Part 1: Rubbing (Martindale) method" adopted by CEN. This…
EN ISO/IEEE 11073-10101:2020/A1:2026
ДействующийHealth informatics - Device interoperability - Part 10101: Point-of-care medical device communication - Nomen…
Overview EN ISO/IEEE 11073-10101:2020/A1:2026 is an amendment to the internationally recognized standard for health informatics and device interoperability, focusing specifically on the nomenclature…
EN ISO 11609:2026
ДействующийDentistry - Dentifrices - Requirements, test methods and marking (ISO 11609:2026)
Overview EN ISO 11609:2026 – Dentistry – Dentifrices – Requirements, Test Methods and Marking (ISO 11609:2026) defines the international requirements for the physical and chemical properties, test me…
EN ISO 20846:2026
ДействующийPetroleum and related products - Determination of sulfur content of automotive fuels - Ultraviolet fluorescen…
Overview EN ISO 20846:2026 is an international standard developed by CEN, specifying a test method for the determination of sulfur content in petroleum and related products, with a focus on automotiv…