IEC TR 80001-2-8:2016 PDF
Application of risk management for IT-networks incorporating medical devices - Part 2-8: Application guidance - Guidance on standards for establishing the security capabilities identified in IEC TR 80001-2-2
Application of risk management for IT-networks incorporating medical devices - Part 2-8: Application guidance - Guidance on standards for establishing the security capabilities identified in IEC TR 80001-2-2
- Статус документа:
- D
- Формат:
- Электронный (PDF)
- Количество страниц:
- 51
- Дата публикации:
- 19 мая 2016 г.
- Издание:
- IEC TR 80001 edition 1 version 1
- ICS:
- 11.040.01
IEC TR 80001-2-8:2016, which is a Technical Report, provides guidance to Health Delivery Organizations (HDOs) and Medical Device Manufacturers (MDMs) for the application of the framework outlined in IEC TR 80001-2-2.
Abstract
Overview
IEC TR 80001-2-8:2016 is a Technical Report from the IEC that gives practical guidance for applying the security framework described in IEC TR 80001-2-2. It supports the overall IEC 80001 series on risk management for IT‑networks incorporating medical devices by mapping security capabilities to concrete security controls. The report is intended for both Health Delivery Organizations (HDOs) and Medical Device Manufacturers (MDMs) to help implement, assess and negotiate security requirements for medical device IT networks.
Key Topics
- Purpose: Guidance on standards and controls needed to establish the security capabilities defined in IEC TR 80001-2-2.
- Shared responsibility: Emphasizes joint roles of HDOs and MDMs in risk management and maintaining secure medical device IT‑networks.
- Catalogue of security capabilities and controls: The report details 19 capability areas (examples below) with requirement goals and user needs:
- Automatic logoff (ALOF), Audit controls (AUDT), Authorization (AUTH)
- Configuration of security features (CNFS), Cyber security product upgrades (CSUP)
- Data backup & disaster recovery (DTBK), Emergency access (EMRG)
- Health data confidentiality, integrity & de-identification (STCF, IGAU, DIDT)
- Malware detection/protection (MLDP), Node and person authentication (NAUT, PAUT)
- System/application hardening (SAHD), Security guides (SGUD), Transmission confidentiality/integrity (TXCF, TXIG), and others.
- Mapping to standards: Identifies security controls drawn from established security standards to help organizations select appropriate technical, administrative and operational measures.
- Scalability: Designed to be adaptable across different HDO sizes and device contexts-controls can be selected based on risk appetite and resources.
Applications
- Procurement and vendor contracts: Use the controls catalogue to specify security requirements in device purchase and service agreements.
- Risk assessments and responsibility agreements: Facilitate stakeholder discussions, define responsibilities, and document residual risk.
- Design and product lifecycle: Guide MDMs on secure product features (updates, authentication, logging) and roadmaps for third‑party components.
- Operational security and incident preparedness: Inform HDO policies for backups, disaster recovery, malware protection and emergency access procedures.
- Regulatory & compliance support: Assist organizations in aligning device-network risk management with recognized best practices.
Related standards
- IEC 80001‑1 (risk management for IT‑networks incorporating medical devices)
- IEC TR 80001‑2‑2 (security capability definitions and disclosure guidance)
- The report also references controls from widely used information security frameworks (examples include ISO/IEC 27001 and other sector standards) to provide practical mapping guidance.
IEC TR 80001-2-8:2016 is a practical reference for teams implementing medical device cybersecurity controls, improving vendor‑HDO collaboration and embedding risk‑based security into device networks.
Технические детали
- Технический комитет
- SC 62A - Common aspects of medical equipment, software, and systems
- SKU
- IEC TR 80001-2-8:2016
Похожие стандарты
Стандарты, упомянутые в описании
PD ISO/TR 80001-2-7:2015
Application of risk management for IT-networks incorporating medical devices. Application guidance - Guidance…
1 Scope The purpose of this part of ISO/TR 80001 is to provide guidance to HDOs on self-assessment of their conformance against IEC 80001-1. The purpose of this part of ISO/TR 80001 is to a) provide…
IEC 80001-1:2021
ДействующийApplication of risk management for IT-networks incorporating medical devices — Part 1: Safety, effectiveness…
Overview IEC 80001-1:2021 - Safety, effectiveness and security in the implementation and use of connected medical devices or connected health software (Part 1: Application of risk management) is a do…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…