ISO/IEEE 11073-40102:2022 PDF
Health informatics — Device interoperability — Part 40102: Foundational — Cybersecurity — Capabilities for mitigation
Health informatics — Device interoperability — Part 40102: Foundational — Cybersecurity — Capabilities for mitigation
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 19
- Дата публикации:
- 17 марта 2022 г.
- Издание:
- ISO/IEEE IS 11073 edition 1 version 1
- ICS:
- 35.240.80
Within the context of secure plug-and-play interoperability, cybersecurity is the process and capability of preventing unauthorized access or modification, misuse, denial of use, or the unauthorized use of information that is stored on, accessed from, or transferred to and from a PHD/PoCD. The capability part of cybersecurity is information security controls related to both digital data and the relationships to safety and usability. For PHDs/PoCDs, this standard defines a security baseline of application layer cybersecurity mitigation techniques for certain use cases or for times when certain criteria are met. This standard provides a scalable information security toolbox appropriate for PHD/PoCD interfaces, which fulfills the intersection of requirements and recommendations from National Institute of Standards and Technology (NIST) and the European Network and Information Security Agency (ENISA). This standard maps to the NIST cybersecurity framework [B15]; IEC TR 80001-2-2 [B8]; and the Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE) classification scheme. The mitigation techniques are based on the extended CIA triad (Clause 4) and are described generally to allow manufacturers to determine the most appropriate algorithms and implementations.
Abstract
Overview
ISO/IEEE 11073-40102:2022 - Health informatics, Device interoperability, Part 40102: Foundational - Cybersecurity - Capabilities for mitigation defines an application-layer security baseline for Personal Health Devices (PHDs) and Point-of-Care Devices (PoCDs) within secure plug-and-play interoperability environments. The standard describes a scalable information security toolbox of mitigation techniques focused on preventing unauthorized access, modification, misuse, denial of use, or unauthorized information disclosure while recognizing the relationship between cybersecurity, safety, and usability.
Key topics and technical requirements
- Application-layer mitigation techniques: General descriptions of controls so manufacturers can select appropriate algorithms and implementations rather than prescribing specific cryptographic algorithms.
- Extended CIA triad: Security measures mapped to confidentiality, integrity and availability, extended to cover device- and healthcare-specific concerns.
- Scalable security toolbox: A set of controls appropriate for PHD/PoCD interfaces and varying use-case severity or criteria.
- Risk and threat mapping: Alignment with threat classifications such as STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege).
- Standards mapping and harmonization: Guidance to fulfill requirements and recommendations from NIST and ENISA, and to map to frameworks such as the NIST Cybersecurity Framework and IEC TR 80001-2-2.
- Focus on interoperability: Emphasis on secure, plug-and-play communications between devices and managing information security at the device interface layer.
- Manufacturer responsibility: Provides baseline capabilities; implementers determine algorithms, key management, and operational detail based on their risk assessment.
Practical applications and who uses it
ISO/IEEE 11073-40102 is practical for:
- Medical device manufacturers designing PHDs and PoCDs to ensure interoperable and secure data exchange.
- System integrators and IoT platform vendors implementing secure plug-and-play interfaces for clinical and consumer health ecosystems.
- Healthcare IT and cybersecurity teams performing risk assessments, threat modeling, and mitigation selection for device integrations.
- Regulatory, procurement, and standards specialists who need a baseline for device cybersecurity expectations and vendor evaluation.
- Test labs and certification bodies validating application-layer cybersecurity capabilities in interoperability scenarios.
Typical uses:
- Selecting mitigation controls during product design and development
- Mapping device capabilities to organizational or national cybersecurity frameworks
- Informing secure interoperability test plans and conformity assessment
- Demonstrating a standards-based security baseline to customers and partners
Related standards
- NIST Cybersecurity Framework (mapping provided)
- IEC TR 80001-2-2 (medical network risk guidance)
- STRIDE threat classification (threat-to-mitigation alignment)
- Other parts of the ISO/IEEE 11073 series (device interoperability family)
Keywords: ISO/IEEE 11073-40102, cybersecurity, device interoperability, Personal Health Devices, Point-of-Care Devices, mitigation techniques, NIST, ENISA, STRIDE, CIA triad.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- ISO/IEEE 11073-40102:2022
Похожие стандарты
Другие стандарты ISO
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…
ISO/ASTMTR52917-EB
ДействующийAdditive Manufacturing — Round Robin Testing — General Guidelines
This document outlines the steps with regard to aspects of design to conduct and run a round robin study (RRS) to assess the degree of variability in an additive manufacturing material or process. Th…
ISO/ASTM52901-17(2023)
ДействующийStandard Guide for Additive Manufacturing – General Principles – Requirements for Purchased AM Parts
Scope 1.1 This document defines and specifies requirements for purchased parts made by additive manufacturing. 1.2 It gives guidelines for the elements to be exchanged between the customer and the pa…