Standards, Guidance & Notices
Showing 31–39 of 39
NIST
IR
IR
IR 8259C
Creating a Profile Using the IoT Core Baseline and Non-Technical Baseline
The core baseline in NISTIR 8259A, IoT Device Cybersecurity Capability Core Baseline and the non-technical baseline in NISTIR 8259B, IoT Manufacturer Non-Technical Supporting Capability Core Baseline can be expanded upon based on more specific contextual information. Using source material with information pertinent to IoT device customers’ needs and goals, the central concepts of the NISTIR 8259 series can be used to guide the development of new elaboration on device cybersecurity capabilities an IoT device may need and the non-technical supporting capabilities that may be needed in relation to the IoT device. This process of expanding on the core baseline and non-technical baseline using additional contextual information is called profiling. A process by which readers of the NISTIR 8259 series can profile source documents is described in this publication.
Published: 2020-12-15
NIST
SP
SP
SP 800-53B
Control Baselines for Information Systems and Organizations
This publication provides security and privacy control baselines for the Federal Government. There are three security control baselines (one for each system impact level—low-impact, moderate-impact, and high-impact), as well as a privacy baseline that is applied to systems irrespective of impact level. In addition to the control baselines, this publication provides tailoring guidance and a set of working assumptions that help guide and inform the control selection process. Finally, this publication provides guidance on the development of overlays to facilitate control baseline customization for specific communities of interest, technologies, and environments of operation.
Published: 2020-12-10
EU
MDCG
MDCG
MDCG 2019-16 rev.1
Guidance on cybersecurity for medical devices
Explains how manufacturers meet the cybersecurity-related general safety and performance requirements (GSPRs) in Annex I of the MDR (2017/745) and IVDR (2017/746) across the full device lifecycle, for medical devices and IVDs that include programmable electronic systems or software -- SaMD, embedded software, mobile apps, networked devices, and systems relying on hospital networks or cloud services. Its central principle is that "security is part of safety and risk management," and it distinguishes between (1) built-in security capabilities -- authentication, authorization, integrity protection, logging, backup/recovery, and secure update mechanisms -- and (2) security information that must be documented, covering the operating environment, configuration, accounts, network controls, updates and residual risk. Pre-market expectations include linking threat analysis to the safety risk management file, applying defence-in-depth controls (least privilege, strong identity management, protected communications, audit logging), and defining testable operating-environment requirements. Post-market expectations include active monitoring of vulnerability sources (databases, researcher reports, supplier notices, threat intelligence), risk assessment, coordinated disclosure, security updates and communication to users. The guidance frames cybersecurity as a shared responsibility between manufacturer and healthcare provider, while stressing that a manufacturer cannot transfer its own design and regulatory obligations to the hospital or user, and aligns with IMDRF's international guidance on medical device cybersecurity.
Published: 2020-07-01
NIST
IR
IR
IR 8259A
IoT Device Cybersecurity Capability Core Baseline
Device cybersecurity capabilities are cybersecurity features or functions that computing devices provide through their own technical means (i.e., device hardware and software). This publication defines an Internet of Things (IoT) device cybersecurity capability core baseline, which is a set of device capabilities generally needed to support common cybersecurity controls that protect an organization’s devices as well as device data, systems, and ecosystems. The purpose of this publication is to provide organizations a starting point to use in identifying the device cybersecurity capabilities for new IoT devices they will manufacture, integrate, or acquire. This publication can be used in conjunction with NISTIR 8259, Foundational Cybersecurity Activities for IoT Device Manufacturers.
Published: 2020-05-29
NIST
IR
IR
IR 8259
Foundational Cybersecurity Activities for IoT Device Manufacturers
Internet of Things (IoT) devices often lack device cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving how securable the IoT devices they make are by providing necessary cybersecurity functionality and by providing customers with the cybersecurity-related information they need. This publication describes recommended activities related to cybersecurity that manufacturers should consider performing before their IoT devices are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of IoT device compromises and the attacks performed using compromised devices.
Published: 2020-05-29
IMDRF
IMDRF/CYBER WG/N60 FINAL:2020
Principles and Practices for Medical Device Cybersecurity
The first IMDRF document to focus exclusively on medical device cybersecurity. It provides concrete recommendations to all responsible stakeholders, including manufacturers, healthcare providers, and regulators, on the general principles and best practices for the cybersecurity of medical devices, including IVD medical devices. It sets out four general principles (global harmonization, total product life cycle, shared responsibility, and information sharing) and organizes premarket considerations (e.g., building security in at the design stage through threat modeling, and preparing customer security documentation) and postmarket considerations (e.g., vulnerability monitoring and remediation, information sharing, and incident response). It is intended to be considered together with the IMDRF Essential Principles of Safety and Performance (N47) throughout the total product life cycle.
Published: 2020-04-20
NIST
FIPS
FIPS
FIPS 140-3
Security Requirements for Cryptographic Modules
The selective application of technological and related procedural safeguards is an important responsibility of every federal organization in providing adequate security in its computer and telecommunication systems. This standard is applicable to all federal agencies that use cryptographic-based security systems to protect sensitive information in computer and telecommunication systems (including voice systems) as defined in Section 5131 of the Information Technology Management Reform Act of 1996, Public Law 104-106 and the Federal Information Security Management Act of 2002, Public Law 107-347.
This standard shall be used in designing and implementing cryptographic modules that federal departments and agencies operate or are operated for them under contract. The standard provides four increasing, qualitative levels of security intended to cover a wide range of potential applications and environments. The security requirements cover areas related to the s
Published: 2019-03-22
NIST
SP
SP
SP 800-39
Managing Information Security Risk: Organization, Mission, and Information System View
The purpose of Special Publication 800-39 is to provide guidance for an integrated, organization-wide program for managing information security risk to organizational operations (i.e., mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation and use of federal information systems. Special Publication 800-39 provides a structured, yet flexible approach for managing information security risk that is intentionally broad-based, with the specific details of assessing, responding to, and monitoring risk on an ongoing basis provided by other supporting NIST security standards and guidelines. The guidance provided in this publication is not intended to replace or subsume other risk-related activities, programs, processes, or approaches that organizations have implemented or intend to implement addressing areas of risk management covered by other legislation, directives, policies, programmatic initiatives, o
Published: 2011-03-01
FDA
CDRH
CDRH
FDA-Cybersecurity-OTS-2005
Cybersecurity for Networked Medical Devices Containing Off-the-Shelf (OTS) Software
Early FDA guidance (2005) on cybersecurity management of off-the-shelf (OTS) software incorporated into network-connected medical devices. It sets out the division of responsibilities between manufacturers and healthcare facilities and the approach to operating system patching, antivirus protection, and access control. Useful for understanding the regulatory history as a predecessor of the current final cybersecurity guidance (first issued in September 2023 and since revised, including the June 2025 version).
Published: 2005-01-14
