Skip to main content
Back

EVS-EN ISO/IEEE 11073-40102:2022

Health informatics - Device interoperability - Part 40102: Foundational - Cybersecurity - Capabilities for mitigation (ISO/IEEE 11073-40102:2022)

General information

Valid from 18.04.2022
Base Documents
ISO/IEEE 11073-40102:2022; EN ISO/IEEE 11073-40102:2022
Directives or regulations
None

Standard history

Status
Date
Type
Name
Within the context of secure plug-and-play interoperability, cybersecurity is the process and capability of preventing unauthorized access or modification, misuse, denial of use, or the unauthorized use of information that is stored on, accessed from, or transferred to and from a PHD/PoCD. The capability part of cybersecurity is information security controls related to both digital data and the relationships to safety and usability.
For PHDs/PoCDs, this standard defines a security baseline of application layer cybersecurity mitigation techniques for certain use cases or for times when certain criteria are met. This standard provides a scalable information security toolbox appropriate for PHD/PoCD interfaces, which fulfills the intersection of requirements and recommendations from National Institute of Standards and Technology (NIST) and the European Network and Information Security Agency (ENISA). This standard maps to the NIST cybersecurity framework [B15]; IEC TR 80001-2-2 [B8]; and the Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE) classification scheme. The mitigation techniques are based on the extended CIA triad (Clause 4) and are described generally to allow manufacturers to determine the most appropriate algorithms and implementations.

Required fields are indicated with *

*
*
*
PDF
24.40 € incl tax
Paper
24.40 € incl tax
Browse standard from 2.44 € incl tax
Standard monitoring

Customers who bought this item also bought

Main

EVS-EN ISO/IEEE 11073-40101:2022

Health informatics - Device interoperability - Part 40101: Foundational - Cybersecurity - Processes for vulnerability assessment (ISO/IEEE 11073-40101:2022)
Newest version Valid from 18.04.2022
Main + amendment

EVS-EN ISO 13485:2016+A11:2021

Medical devices - Quality management systems - Requirements for regulatory purposes (ISO 13485:2016)
Newest version Valid from 16.09.2021
Main

EVS-EN IEC 80001-1:2021

Application of risk management for IT-networks incorporating medical devices - Part 1: Safety, effectiveness and security in the implementation and use of connected medical devices or connected health software
Newest version Valid from 15.11.2021
Main + amendment

EVS-EN ISO 14971:2019+A11:2021

Medical devices - Application of risk management to medical devices (ISO 14971:2019)
Newest version Valid from 15.12.2021