首页> 外文期刊>Biomedical and Health Informatics, IEEE Journal of >Integrated Security, Safety, and Privacy Risk Assessment Framework for Medical Devices
【24h】

Integrated Security, Safety, and Privacy Risk Assessment Framework for Medical Devices

机译:医疗设备的综合安全,安全和隐私风险评估框架

获取原文
获取原文并翻译 | 示例
           

摘要

The substantial improvements and innovations in communication networks and bio-medical technologies have led to the adoption of networked medical devices due to which the attack surface has increased profoundly. Numerous devices in practice were designed and developed years ago without security measures. In such a scenario, the role of regulatory bodies has become evident. The Food and Drug Administration (FDA) validates and approves devices before commercialization. In contrast, the European Union (EU) follows a decentralized approach and Notified Bodies (NB) for assuring high standards, safety and quality of medical devices being marketed in Europe. Once the device has gone through stringent regulations including good manufacturing practices, Quality Management System (QMS), labeling, clinical tests, performance standards, adequate storage and packaging practices, a declaration of conformity will be granted, which is a legal binding document stating that the device is conformant with applicable European requirements and can be marketed in Europe. However, such regulations lack a systematic methodology to determine unified security, safety and privacy risk that eventually influence the health of patients. To cover these gaps, this research proposes Integrated Safety, Security, and Privacy (ISSP) Risk Assessment Framework to determine the risk level of the device and required security controls. It is, then applied to a case scenario of an infusion pump and further evaluated by comparing it with current standards and practices. The comparison shows that the framework provides a unified approach to consider different types of risks associated with devices.
机译:通信网络和生物医学技术的实质性改进和创新导致了采用网络化医疗器械,因为攻击表面增加了深刻的增加。多年前设计和开发了众多设备,没有安全措施。在这种情况下,监管机构的作用变得明显。食品和药物管理局(FDA)在商业化之前验证和批准设备。相比之下,欧盟(欧盟)遵循分散的方法和通知机构(NB),以确保欧洲销售的高标准,安全和质量。一旦该设备经历了严格的规定,包括良好的制造规则,质量管理系统(QMS),标签,临床试验,性能标准,足够的储存和包装实践,将获得符合性的宣言,这是一个合法的约束文件,说明这一点该设备符合适用的欧洲要求,可在欧洲销售。然而,这些法规缺乏系统的方法,以确定最终影响患者健康的统一安全,安全和隐私风险。为了涵盖这些差距,本研究提出了综合安全,安全和隐私(ISSP)风险评估框架,以确定设备的风险等级和所需的安全控制。然后,通过将其与当前标准和实践进行比较,应用于输液泵的案例场景并进一步评估。比较表明,该框架提供了统一的方法来考虑与设备相关的不同类型的风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号