首页> 外文期刊>Computer standards & interfaces >Cybersecurity and medical devices: Are the ISO/IEC 80001-2-2 technical controls up to the challenge?
【24h】

Cybersecurity and medical devices: Are the ISO/IEC 80001-2-2 technical controls up to the challenge?

机译:网络安全和医疗设备:ISO / IEC 80001-2-2技术控制能否应对挑战?

获取原文
获取原文并翻译 | 示例

摘要

HighlightsAn analysis of technical guidance for cybersecurity of ISO 80001-2-8 is presented.ISO 80001-2-8 technical security controls have significant gaps in areas.ISO 80001-2-8 presents an effective baseline for cybersecurity of medical devices.AbstractMedical devices, in the case of malfunction, can have tangible impact on patient safety. Their security, in a world where the Internet of Things has become a reality, is paramount to the continued safety of patients that are dependent upon these devices. The international standard ISO/IEC 80001 –Application of risk management for IT-networks incorporating medical devicespresents a unified and amalgamated approach to the safety of medical devices connected to IT networks. Whilst this standard presents a guide for security and risk management in health delivery organisations, its effectiveness with regard to contemporary cybersecurity is unknown.This research employed a structured review process to compare and analyse the ISO/IEC 80001 technical controls standards (ISO/IEC 80001-2-2 and ISO/IEC 80001-2-8), with contemporary cybersecurity best practice, guidelines and standards. The research deconstructed the technical controls and drew links between these standards and cybersecurity best practice to assess the level of harmonisation. Subsequently, a deeper analysis identified the areas of omission, coverage, addition or improvement that may impact the effectiveness of ISO/IEC 80001 to provide effective cybersecurity protection.ISO/IEC 80001 aims to provide a minimal level of cybersecurity however this research demonstrates that there are deficiencies in the standard and identifies the important aspects of cybersecurity that could be improved. This situation has arisen due to the rapidly evolving nature of the cybersecurity environment and the protracted time to revise and republish international standards. This research identified several areas that require urgent consideration, including Emergency Access, Health Data De-Identification, Physical Locks on Devices, Data Backup, Disaster Recovery, Third-Party Components in Product Lifecycle Roadmap, Transmission Confidentiality, and Transmission Integrity. The research will provide health delivery organisations implementing ISO/IEC 80001, assurance as to the level of protection supplied by the ISO/IEC 80001 standard, and the areas that may need enhancement to increase cybersecurity protection and consequently increase in patient safety. Further, the outcomes are expected to influence development of the related international standard, as the findings from this research are being provided to the International Organisations for Standardisation, TC215 Health Informatics, Joint Working Group 7, to inform the review of ISO/IEC 80001 currently in progress.
机译: 突出显示 分析了ISO 80001-2-8网络安全技术指南。 ISO 80001-2-8技术安全控制在某些方面存在重大差距。 ISO 80001-2-8为医疗设备的网络安全提出了有效的基准。 摘要 在发生故障的情况下,医疗设备可能对患者的安全产生明显影响。在物联网已成为现实的世界中,其安全性对于依赖这些设备的患者的持续安全至为重要。国际标准ISO / IEC 80001 – 结合医疗设备的IT网络的风险管理应用提出了一种统一的方法,用于连接到IT网络的医疗设备的安全性。尽管此标准提供了卫生提供组织中安全和风险管理的指南,但其在当代网络安全方面的有效性尚不清楚。 这项研究采用了结构化的审查流程,以比较和分析ISO / IEC 80001技术控制标准(ISO / IEC 80001-2-2和ISO / IEC 80001-2-8),并结合了现代网络安全最佳实践,指南和标准。该研究对技术控制进行了解构,并在这些标准和网络安全最佳实践之间建立了联系,以评估协调水平。随后,进行了更深入的分析,确定了可能会影响ISO / IEC 80001提供有效网络安全保护的有效性的遗漏,覆盖,添加或改进的区域。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号