Title :
A Security Argument Pattern for Medical Device Assurance Cases
Author :
Finnegan, Anita ; McCaffery, Fergal
Author_Institution :
Regulated Software Res. Centre, Dundalk Inst. of Technol., Dundalk, Ireland
Abstract :
Medical device security is a growing concern for medical device manufacturers, healthcare delivery organisations and regulators in the industry. Increasingly, researchers are demonstrating exactly how vulnerable these devices are. In many cases, networked medical devices are regarded as a potential weak link within a healthcare IT network that could provide a means to expose the entire network to a malware attack. At present there is no formal method for implementing security risk management practices in the medical device industry. However, with new regulatory guidance being developed by the Food and Drug Administration (FDA), medical devices manufacturers will need to prove that their devices are secure. This paper presents a security case framework that is currently under development. The purpose of this framework is to provide medical device manufacturers and healthcare delivery organisations with a solution to assist both in establishing confidence in the security assurance of medical devices and to also maintain this confidence throughout the lifetime of the device.
Keywords :
biomedical equipment; health care; invasive software; medical computing; risk management; FDA; Food and Drug Administration; healthcare IT network; healthcare delivery organisations; malware attack; medical device assurance cases; medical device industry; medical device manufacturers; medical device security; networked medical devices; regulatory guidance; security argument pattern; security risk management practices; IEC standards; ISO standards; Medical diagnostic imaging; Medical services; Safety; Security; assurance cases; cybersecurity; medical device security; security capability argument pattern; security cases;
Conference_Titel :
Software Reliability Engineering Workshops (ISSREW), 2014 IEEE International Symposium on
Conference_Location :
Naples
DOI :
10.1109/ISSREW.2014.89