EN ISO/IEEE 11073-40102:2022 PDF
Health informatics - Device interoperability - Part 40102: Foundational - Cybersecurity - Capabilities for mitigation (ISO/IEEE 11073-40102:2022)
Health informatics - Device interoperability - Part 40102: Foundational - Cybersecurity - Capabilities for mitigation (ISO/IEEE 11073-40102:2022)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 35
- Дата публикации:
- 30 марта 2022 г.
- Издание:
- CEN EN 11073 edition 1 version 1
- ICS:
- 35.240.80
Within the context of secure plug-and-play interoperability, cybersecurity is the process and capability of preventing unauthorized access or modification, misuse, denial of use, or the unauthorized use of information that is stored on, accessed from, or transferred to and from a PHD/PoCD. The capability part of cybersecurity is information security controls related to both digital data and the relationships to safety and usability. For PHDs/PoCDs, this standard defines a security baseline of application layer cybersecurity mitigation techniques for certain use cases or for times when certain criteria are met. This standard provides a scalable information security toolbox appropriate for PHD/PoCD interfaces, which fulfills the intersection of requirements and recommendations from National Institute of Standards and Technology (NIST) and the European Network and Information Security Agency (ENISA). This standard maps to the NIST cybersecurity framework [B15]; IEC TR 80001-2-2 [B8]; and the Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE) classification scheme. The mitigation techniques are based on the extended CIA triad (Clause 4) and are described generally to allow manufacturers to determine the most appropriate algorithms and implementations.
Abstract
Overview
EN ISO/IEEE 11073-40102:2022 - "Health informatics - Device interoperability - Part 40102: Foundational - Cybersecurity - Capabilities for mitigation" provides a security baseline for application‑layer cybersecurity for Personal Health Devices (PHDs) and Point‑of‑Care Devices (PoCDs). Within the secure plug‑and‑play interoperability context, the standard defines cybersecurity as the capabilities to prevent unauthorized access, misuse, modification, denial of use, or unauthorized use of data stored on, accessed from, or transferred to/from PHDs/PoCDs. It supplies a scalable information‑security toolbox described generally so manufacturers can choose appropriate algorithms and implementations.
Key topics and technical requirements
- Application‑layer mitigation techniques: A baseline set of controls and mitigation options for PHD/PoCD interfaces when specific use cases or criteria apply.
- Extended CIA triad: Focus on confidentiality, integrity, availability (extended for device and data contexts) as the organizing security principles (see Clause 4).
- Scalable toolbox: A flexible set of information‑security controls suitable for constrained medical devices and interoperability stacks.
- Threat classification mapping: Alignment with STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) for threat analysis.
- Standards mapping and alignment: Cross‑references and mappings to the NIST Cybersecurity Framework, ENISA guidance, and IEC TR 80001‑2‑2 to harmonize device‑level controls with broader cybersecurity practices.
- Implementation neutrality: Techniques are described generally (not mandating algorithms or cipher suites), allowing vendors to select technologies appropriate to device capabilities and regulatory constraints.
Practical applications and intended users
- Device manufacturers: adopt an interoperable, application‑layer security baseline for PHD and PoCD product design and firmware.
- System integrators and healthcare IT teams: apply mitigation techniques to ensure secure plug‑and‑play device interoperability in clinical networks.
- Medical device cybersecurity engineers: use the toolbox to perform threat modeling (STRIDE) and to map mitigations to the extended CIA objectives.
- Regulators and risk managers: reference the standard when assessing conformity with NIST/ENISA‑aligned cybersecurity expectations for personal and point‑of‑care devices.
Related standards
- NIST Cybersecurity Framework - mapped for controls and lifecycle alignment.
- IEC TR 80001‑2‑2 - guidance on risk management for medical IT networks.
- IEEE 11073 family - device interoperability standards family context.
This standard is essential for teams building or integrating interoperable medical devices who need a practical, standards‑aligned approach to application‑layer cybersecurity for PHDs and PoCDs. Keywords: cybersecurity, device interoperability, IEEE 11073-40102, PHD, PoCD, mitigation techniques, STRIDE, CIA triad, NIST, ENISA.
Технические детали
- Технический комитет
- CEN/TC 251 - Medical informatics
- SKU
- EN ISO/IEEE 11073-40102:2022
Похожие стандарты
Другие стандарты EN
EN ISO 6599-1:2026
ДействующийPackaging - Conditioning for testing - Part 1: Paper sacks (ISO 6599-1:2026)
Overview EN ISO 6599-1:2026 - Packaging - Conditioning for testing - Part 1: Paper sacks is a key international standard developed by CEN and ISO. This document defines the conditioning atmospheres a…
EN ISO 4885:2026
ДействующийFerrous materials - Heat treatments - Vocabulary (ISO 4885:2026)
Overview EN ISO 4885:2026 - Ferrous Materials – Heat Treatments – Vocabulary is an international standard developed by CEN, aligning with ISO 4885:2026. This document provides comprehensive definitio…
EN ISO/IEC 29151:2026
ДействующийInformation security, cybersecurity and privacy protection - Controls, requirements, and guidance for persona…
Overview EN ISO/IEC 29151:2026 specifies controls, requirements, and guidance to ensure the proper protection of personally identifiable information (PII) within the fields of information security, c…
EN ISO 9693:2026
ДействующийDentistry - Compatibility testing for metal-ceramic and ceramic-ceramic systems (ISO 9693:2026)
Overview EN ISO 9693:2026 - Dentistry: Compatibility Testing for Metal-Ceramic and Ceramic-Ceramic Systems establishes internationally recognized requirements and test methods for evaluating the ther…
EN ISO 26082-1:2026
ДействующийLeather - Physical and mechanical test methods for the determination of soiling - Part 1: Rubbing (Martindale…
Overview EN ISO 26082-1:2026 is a European standard titled "Leather - Physical and mechanical test methods for the determination of soiling - Part 1: Rubbing (Martindale) method" adopted by CEN. This…
EN ISO/IEEE 11073-10101:2020/A1:2026
ДействующийHealth informatics - Device interoperability - Part 10101: Point-of-care medical device communication - Nomen…
Overview EN ISO/IEEE 11073-10101:2020/A1:2026 is an amendment to the internationally recognized standard for health informatics and device interoperability, focusing specifically on the nomenclature…
EN ISO 11609:2026
ДействующийDentistry - Dentifrices - Requirements, test methods and marking (ISO 11609:2026)
Overview EN ISO 11609:2026 – Dentistry – Dentifrices – Requirements, Test Methods and Marking (ISO 11609:2026) defines the international requirements for the physical and chemical properties, test me…
EN ISO 20846:2026
ДействующийPetroleum and related products - Determination of sulfur content of automotive fuels - Ultraviolet fluorescen…
Overview EN ISO 20846:2026 is an international standard developed by CEN, specifying a test method for the determination of sulfur content in petroleum and related products, with a focus on automotiv…