Search
×
FR

Placeholder headline

This is just a placeholder headline

API STD 521: Guide for Pressure-relieving and Depressuring Systems – Edition 6

$

682

BUY NOW

Placeholder headline

This is just a placeholder headline

API STD 653: Tank Inspection, Repair, Alteration, and Reconstruction – Edition 4

$

507

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z662:19 – Oil and gas pipeline systems

$

1197

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z341 Series-18: Storage of hydrocarbons in underground formations

$

878

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z246.2-14 – Emergency preparedness and response for petroleum and natural gas industry systems

$

596

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z341 Series:22 – Storage of hydrocarbons in underground formations

$

878

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z731-09 (R2014) – Emergency Preparedness and Response

$

177

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z662:23 – Oil and gas pipeline systems

$

1197

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA Z341 Series:26 – Storage of Hydrocarbons in underground formations

$

878

BUY NOW

Placeholder headline

This is just a placeholder headline

CSA B51:24 Boiler, Pressure Vessel, and Pressure Piping Code

$

389

BUY NOW

ISO 80001:2017

ISO 80001:2017 Application of risk management for IT-networks incorporating medical devices – Part 2-9: Application guidance – Guidance for use of security assurance cases to demonstrate confidence in IEC/TR 80001-2-2 security capabilities

CDN $464.00

SKU: 53562d51543f Categories: ,

Description

IEC TR 80001-2-9:2017(E) establishes a security case framework and provides guidance to health care delivery organizations (HDO) and medical device manufacturers (MDM) for identifying, developing, interpreting, updating and maintaining security cases for networked medical devices. Use of this part of 80001 is intended to be one of the possible means to bridge the gap between MDMs and HDOs in providing adequate information to support the HDOs risk management of IT-networks. This document leverages the requirements set out in ISO/IEC 15026-2 for the development of assurance cases. It is not intended that this security case framework will replace a risk management strategy, rather, the intention is to complement risk management and in turn provide a greater level of assurance for a medical device by:
– mapping specific risk management steps to each of the IEC TR 80001-2-2 security capabilities, identifying associated threats and vulnerabilities and presenting them in the format of a security case with the inclusion of a re-useable security pattern;
– providing guidance for the selection of appropriate security controls to establish security capabilities and presenting them as part of the security case pattern (IEC TR 80001-2-8 provides examples of such security controls);
– providing evidence to support the implementation of a security control, hence providing confidence in the establishment of each of the security capabilities.
The purpose of developing the security case is to demonstrate confidence in the establishment of IEC TR 80001-2-2 security capabilities. The quality of artifacts gathered and documented during the development of the security case is agreed and documented as part of a responsibility agreement between the relevant stakeholders. This document provides guidance for one such methodology, through the use of a specific security pattern, to develop and interpret security cases in a systematic manner.

Edition

1

Published Date

2017-08-02

Status

PUBLISHED

Pages

28

Language Detail Icon

English

Format Secure Icon

Secure PDF

Abstract

IEC TR 80001-2-9:2017(E) establishes a security case framework and provides guidance to health care delivery organizations (HDO) and medical device manufacturers (MDM) for identifying, developing, interpreting, updating and maintaining security cases for networked medical devices. Use of this part of 80001 is intended to be one of the possible means to bridge the gap between MDMs and HDOs in providing adequate information to support the HDOs risk management of IT-networks. This document leverages the requirements set out in ISO/IEC 15026-2 for the development of assurance cases. It is not intended that this security case framework will replace a risk management strategy, rather, the intention is to complement risk management and in turn provide a greater level of assurance for a medical device by: - mapping specific risk management steps to each of the IEC TR 80001-2-2 security capabilities, identifying associated threats and vulnerabilities and presenting them in the format of a security case with the inclusion of a re-useable security pattern; - providing guidance for the selection of appropriate security controls to establish security capabilities and presenting them as part of the security case pattern (IEC TR 80001-2-8 provides examples of such security controls); - providing evidence to support the implementation of a security control, hence providing confidence in the establishment of each of the security capabilities. The purpose of developing the security case is to demonstrate confidence in the establishment of IEC TR 80001-2-2 security capabilities. The quality of artifacts gathered and documented during the development of the security case is agreed and documented as part of a responsibility agreement between the relevant stakeholders. This document provides guidance for one such methodology, through the use of a specific security pattern, to develop and interpret security cases in a systematic manner.

Previous Editions

Can’t find what you are looking for?

Please contact us at: