ISO/IEEE 11073-40101:2022 PDF
Health informatics — Device interoperability — Part 40101: Foundational — Cybersecurity — Processes for vulnerability assessment
Health informatics — Device interoperability — Part 40101: Foundational — Cybersecurity — Processes for vulnerability assessment
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 38
- Дата публикации:
- 17 марта 2022 г.
- Издание:
- ISO/IEEE IS 11073 edition 1 version 1
- ICS:
- 35.240.80
Within the context of secure plug-and-play interoperability, cybersecurity is the process and capability of preventing unauthorized access or modification, misuse, denial of use, or the unauthorized use of information that is stored on, accessed from, or transferred to and from a PHD/PoCD. The process part of cybersecurity is risk analysis of use cases specific to a PHD/PoCD. For PHDs/PoCDs, this standard defines an iterative, systematic, scalable, and auditable approach to identification of cybersecurity vulnerabilities and estimation of risk. This iterative vulnerability assessment uses the Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE) classification scheme and the embedded Common Vulnerability Scoring System (eCVSS). The assessment includes system context, system decomposition, pre-mitigation scoring, mitigation, and post-mitigation scoring and iterates until the remaining vulnerabilities are reduced to an acceptable level of risk.
Abstract
Overview - ISO/IEEE 11073-40101:2022 (Cybersecurity - Vulnerability Assessment)
ISO/IEEE 11073-40101:2022 defines a foundational, auditable process for cybersecurity vulnerability assessment applied to Personal Health Devices (PHDs) and Point‑of‑Care Devices (PoCDs) within the context of secure plug‑and‑play device interoperability. The standard prescribes an iterative, systematic, scalable approach to identify vulnerabilities and estimate risk, using well‑known threat and scoring frameworks to drive repeatable pre‑ and post‑mitigation analysis until residual risk is acceptable.
Key topics and technical requirements
- Scope & purpose: Risk analysis of use cases specific to a PHD/PoCD to prevent unauthorized access, modification, misuse, denial of use, or unauthorized use of device data.
- Iterative assessment lifecycle: Includes establishment of system context, system decomposition, pre‑mitigation scoring, design and application of mitigations, and post‑mitigation scoring - repeated until acceptable residual risk.
- Threat classification: Uses the STRIDE taxonomy (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) to categorize vulnerabilities.
- Risk scoring: Integrates an embedded Common Vulnerability Scoring System (eCVSS) for quantitative pre‑ and post‑mitigation scoring to support prioritization and auditability.
- Scalability & auditability: Process is designed to scale across device types and development lifecycles and to produce records suitable for regulatory review, supplier communication, and security testing.
- Contextual analysis: Emphasizes device/system context and use‑case driven threat modeling rather than generic checklist approaches.
Practical applications
- Secure development and risk management for medical device manufacturers building PHDs and PoCDs.
- Cybersecurity teams conducting vulnerability assessments, threat modeling, and remediation tracking for interoperable medical devices.
- Clinical engineers, integrators, and healthcare IT architects validating device behavior in plug‑and‑play environments.
- Test labs and conformity assessors using structured, auditable scoring to evaluate device security posture.
- Procurement and risk officers requiring documented evidence of vulnerability assessment in supplier submissions.
Who should use this standard
- Medical device manufacturers, firmware and software developers
- Device integrators and clinical systems engineers
- Cybersecurity risk managers and penetration testers focused on health informatics
- Regulatory and compliance teams assessing device security evidence
Related standards and keywords
- Part of the ISO/IEEE 11073 device interoperability family (see ISO website for other parts)
- Related concepts/tools: STRIDE, eCVSS, vulnerability assessment, medical device cybersecurity, device interoperability, health informatics, PHD, PoCD
Implementers should align the standard’s processes with applicable laws, regulatory requirements, and organizational risk acceptance criteria.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- ISO/IEEE 11073-40101:2022
Похожие стандарты
Другие стандарты ISO
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…
ISO/ASTMTR52917-EB
ДействующийAdditive Manufacturing — Round Robin Testing — General Guidelines
This document outlines the steps with regard to aspects of design to conduct and run a round robin study (RRS) to assess the degree of variability in an additive manufacturing material or process. Th…
ISO/ASTM52901-17(2023)
ДействующийStandard Guide for Additive Manufacturing – General Principles – Requirements for Purchased AM Parts
Scope 1.1 This document defines and specifies requirements for purchased parts made by additive manufacturing. 1.2 It gives guidelines for the elements to be exchanged between the customer and the pa…