Transcription of Principles and Practices for Medical Device Cybersecurity
1 IMDRF/CYBER WG/N60 FINAL:2020. International Medical IMDRF Device Regulators Forum FINAL DOCUMENT. Title: Principles and Practices for Medical Device Cybersecurity Authoring Group: Medical Device Cybersecurity Working Group Date: 18 March 2020. Dr Choong May Ling, Mimi, IMDRF Chair This document was produced by the International Medical Device Regulators Forum. There are no restrictions on the reproduction or use of this document; however, incorporation of this document, in part or in whole, into another document, or its translation into languages other than English, does not convey or represent an endorsement of any kind by the International Medical Device Regulators Forum.
2 Cop):right 2020 by the International Medical Device Regulators Forum. IMDRF/CYBER WG/N60 FINAL:2020. Table of Contents Introduction .. 5. Scope .. 5. 6. General Principles .. 9. Global Harmonization .. 9. Total Product Life Cycle .. 9. Shared 10. Information Sharing .. 10. Pre-Market Considerations for Medical Device Cybersecurity .. 10. Security Requirements and Architecture design .. 10. Risk Management Principles for the TPLC .. 13. Security 15. TPLC Cybersecurity Management Plan .. 16. Labeling and Customer Security Documentation.
3 16. Labeling .. 16. Customer Security Documentation .. 17. Documentation for Regulatory Submission .. 18. design Documentation .. 18. Risk Ma+agement Documentation .. 18. Security Testing Documentation .. 18. TPLC Cybersecurity Management Planning Documentation .. 19. Labelling and Customer Security 19. Post-Market Considerations for Medical Device Cybersecurity .. 19. Operating Devices in the Intended Use Environment .. 19. Healthcare Providers and Patients .. 19. Medical Device Manufacturers.
4 20. Information Sharing .. 20. Key 21. Key Stakeholders .. 21. Types of Information .. 22. Trusted Communication .. 23. Coordinated Vulnerability Disclosure .. 23. 18 March 2020 Page 2 of 46. IMDRF/CYBER WG/N60 FINAL:2020. Medical Device Manufacturers .. 23. Regulators .. 24. Vulnerability Finders (includes security researchers and others) .. 25. Vulnerability Remediation .. 25. Medical Device Manufacturers .. 25. Healthcare Providers and Patients .. 27. Regulators .. 30. Incident Response .. 32.
5 Medical Device Manufacturers .. 32. Healthcare 33. Medical Device Regulators .. 34. Legacy Medical Devices .. 34. Medical Device Manufacturers .. 35. Healthcare 37. References .. 38. IMDRF Documents .. 38. Standards .. 38. Regulatory Guidance .. 39. Other Resources and References .. 40. Appendices .. 42. Appendix A: Incident Response Roles (from ISO/IEC 27035) .. 43. Appendix B: Jurisdictional resources for Coordinated Vulnerability Disclosure .. 45. 18 March 2020 Page 3 of 46. IMDRF/CYBER WG/N60 FINAL:2020.
6 Preface The document herein was produced by the International Medical Device Regulators Forum (IMDRF), a voluntary group of Medical Device regulators from around the world. The document has been subject to consultation throughout its development. There are no restrictions on the reproduction, distribution or use of this document; however, incorporation of this document, in part or in whole, into any other document, or its translation into languages other than English, does not convey or represent an endorsement of any kind by the International Medical Device Regulators Forum.
7 18 March 2020 Page 4 of 46. IMDRF/CYBER WG/N60 FINAL:2020. Introduction The need for effective Cybersecurity to ensure Medical Device functionality and safety has become more important with the increasing use of wireless, Internet, and network-connected devices. Cybersecurity incidents have rendered Medical devices and hospital networks inoperable, disrupting the delivery of patient care across healthcare facilities. Such incidents may lead to patient harm through delays and/or errors in diagnoses and/or treatment interventions, etc.
8 Stakeholders within the healthcare sector have a shared responsibility regarding Medical Device Cybersecurity . This guidance intends to assist all stakeholders in gaining a better understanding of their role in support of proactive Cybersecurity that helps protect and secure Medical devices in anticipation of future attacks, problems, or events. Convergence of global healthcare Cybersecurity Principles and Practices is necessary to ensure that patient safety and Medical Device performance is maintained.
9 To date, however, current disparate regulations across governments lack the global alignment needed to ensure Medical Device Cybersecurity . The purpose of this IMDRF guidance document is to provide general Principles and best Practices to facilitate international regulatory convergence on Medical Device Cybersecurity . The document is structured as follows: the scope of the document is defined in Section 2 followed by defined terms in Section 3. Section 4 provides an overview of the general Principles of Medical Device Cybersecurity , while Sections 5 and 6 provide a number of recommendations for stakeholders regarding best Practices in the pre-market and post-market management of Medical Device Cybersecurity .
10 While the pre-market section primarily addresses Medical Device manufacturers, the post-market section includes recommendations for all stakeholders. This is the first IMDRF guidance document to focus exclusively on Medical Device Cybersecurity . However, there are other relevant IMDRF documents which should be noted in terms of general security considerations. IMDRF/GRRP WG/N47 FINAL:2018 provides harmonized Essential Principles that should be fulfilled in the design and manufacturing of Medical devices and IVD.