AAMI規格 AAMI TIR57, 2016/(R)2023: Technical Information Report: Principles for medical device security-Risk management, 技術情報レポート: 医療機器のセキュリティの原則 - リスク管理
Description
This TIR provides guidance for addressing information security within the risk management framework defined by ANSI/AAMI/ISO 14971.
This guidance is intended to assist manufacturers and other users of the standard in the following:
- identifying threats, vulnerabilities, and assets associated with medical devices;
- estimating and evaluating associated security risks;
- controlling security risks; and
- monitoring effectiveness of the risk controls.
This document is based on an application of ANSI/AAMI/ISO 14971 with an expanded consideration of the possible impacts that a security compromise can have on the medical device, people, the environment, the manufacturer, and the information processed and stored by the device. This report also incorporates several principles from NIST SP 800-30 Revision 1 (see Bibliography [53]), a security risk management process developed for traditional IT systems.
The guidance provided by this document is applicable to all stages of the life-cycle of a medical device.