Standards, Guidance & Notices
Showing 31–40 of 49
NIST
FIPS
FIPS
FIPS 186-5
Digital Signature Standard (DSS)
This standard specifies a suite of algorithms that can be used to generate a digital signature. Digital signatures are used to detect unauthorized modifications to data and to authenticate the identity of the signatory. In addition, the recipient of signed data can use a digital signature as evidence in demonstrating to a third party that the signature was, in fact, generated by the claimed signatory. This is known as non-repudiation since the signatory cannot easily repudiate the signature at a later time.
Published: 2023-02-03
AAMI
TIR
TIR
AAMI TIR97:2019/(R)2023
Principles for medical device security — Postmarket risk management for device manufacturers
Technical information report providing guidance on postmarket security risk management for medical devices within the ISO 14971 safety risk management process. Designed for use with AAMI TIR57:2016. Covers PSIRT establishment, vulnerability disclosure policy, and coordinated vulnerability disclosure (CVD) frameworks. Closely aligned with FDA postmarket cybersecurity guidance. Published 2019, reaffirmed 2023.
Published: 2023-01-31
AAMI
TIR
TIR
AAMI TIR57:2016/(R)2023
Principles for medical device security — Risk management
Technical information report providing guidance on information security risk management for medical devices within the ISO 14971 safety risk management process. Incorporates expanded risk management concepts from IEC 62443, presenting practical methods for threat modeling and security risk assessment. Directly referenced by FDA's 2023 final cybersecurity guidance. Complementary to IEC 81001-5-1. Originally published 2016, reaffirmed 2023.
Published: 2023-01-13
NIST
SP
SP
SP 800-40 Rev. 4
Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology
Enterprise patch management is the process of identifying, prioritizing, acquiring, installing, and verifying the installation of patches, updates, and upgrades throughout an organization. Patching is more important than ever because of the increasing reliance on technology, but there is often a divide between business/mission owners and security/technology management about the value of patching. This publication frames patching as a critical component of preventive maintenance for computing technologies – a cost of doing business, and a necessary part of what organizations need to do in order to achieve their missions. This publication also discusses common factors that affect enterprise patch management and recommends creating an enterprise strategy to simplify and operationalize patching while also improving reduction of risk. Preventive maintenance through enterprise patch management helps prevent compromises, data breaches, operational disruptions, and other adverse events.
Published: 2022-04-06
NIST
SP
SP
SP 1800-30
Securing Telehealth Remote Patient Monitoring Ecosystem
Increasingly, healthcare delivery organizations (HDOs) are relying on telehealth and remote patient monitoring (RPM) capabilities to treat patients at home. RPM is convenient and cost-effective, and its adoption rate has increased. However, without adequate privacy and cybersecurity measures, unauthorized individuals may expose sensitive data or disrupt patient monitoring services.
RPM solutions engage multiple actors as participants in patients’ clinical care. These actors include HDOs, telehealth platform providers, and the patients themselves. Each participant uses, manages, and maintains different technology components within an interconnected ecosystem, and each is responsible for safeguarding their piece against unique threats and risks associated with RPM technologies.
This practice guide assumes that the HDO engages with a telehealth platform provider that is a separate entity from the HDO and patient. The telehealth platform provider manages a distinct infrastructure, applic
Published: 2022-02-22
IEC
IEC 81001-5-1:2021
Health software and health IT systems safety, effectiveness and security — Part 5-1: Security — Activities in the product life cycle
Establishes a common framework for secure health software life cycle processes. Defines security activities and tasks to increase cybersecurity of health software.
Published: 2021-12-01
NIST
SP
SP
SP 800-213
IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements
Organizations will increasingly use Internet of Things (IoT) devices for the mission benefits they can offer, but care must be taken in the acquisition and implementation of IoT devices. This publication contains background and recommendations to help organizations consider how an IoT device they plan to acquire can integrate into a system. IoT devices and their support for security controls are presented in the context of organizational and system risk management. This publication provides guidance on considering system security from the device perspective. This allows for the identification of device cybersecurity requirements—the abilities and actions an organization will expect from an IoT device and its manufacturer and/or third parties, respectively.
Published: 2021-11-29
NIST
SP
SP
SP 800-213A
IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog
This publication provides a catalog of internet of things (IoT) device cybersecurity capabilities (i.e., features and functions needed from a device to support security controls) and non-technical supporting capabilities (i.e., actions and support needed from device manufacturers and other supporting entities to support security controls) that can help organizations as they use Special Publication (SP) 800-213 to determine and establish device cybersecurity requirements. This catalog cross references the capabilities in the catalog to the cybersecurity controls in NIST SP 800-53. Organizations should refer to SP 800-213 as that publication provides necessary context to effectively use this catalog and related material.
Published: 2021-11-29
NIST
IR
IR
IR 8259B
IoT Non-Technical Supporting Capability Core Baseline
Non-technical supporting capabilities are actions a manufacturer or third-party organization performs in support of the cybersecurity of an IoT device. This publication defines an Internet of Things (IoT) device manufacturers’ non-technical supporting capability core baseline, which is a set of non-technical supporting capabilities generally needed from manufacturers or other third parties to support common cybersecurity controls that protect an organization’s devices as well as device data, systems, and ecosystems. The purpose of this publication is to provide organizations a starting point to use in identifying the non-technical supporting capabilities needed in relation to IoT devices they will manufacture, integrate, or acquire. This publication is intended to be used in conjunction with NISTIR 8259, Foundational Cybersecurity Activities for IoT Device Manufacturers and NISTIR 8259A, IoT Device Cybersecurity Capability Core Baseline.
Published: 2021-08-25
NIST
SP
SP
SP 1800-24
Securing Picture Archiving and Communication System (PACS): Cybersecurity for the Healthcare Sector
Medical imaging plays an important role in diagnosing and treating patients. The system that manages medical images is known as the picture archiving communication system (PACS) and is nearly ubiquitous in healthcare environments. PACS is defined by the Food and Drug Administration (FDA) as a Class II device that “provides one or more capabilities relating to the acceptance, transfer, display, storage, and digital processing of medical images.” PACS centralizes functions surrounding medical imaging workflows and serves as an authoritative repository of medical image information.
PACS fits within a highly complex healthcare delivery organization (HDO) environment that involves interfacing with a range of interconnected systems. PACS may connect with clinical information systems and medical devices and engage with HDO-internal and affiliated health professionals. Complexity may introduce or expose opportunities that allow malicious actors to compromise the confidentiality, integrity, an
Published: 2020-12-21
