LIVE — Last crawled: 2026-08-13 17:29 JST
Vol.1 — August 14, 2026
MSC Portal Regulatory Watch All Entries (4)
Standards, Guidance & Notices
Showing 1–4 of 4
NIST
SP
SP 800-161 Rev. 1
Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
PUBLISHED NEW SBOM / Vulnerability
Organizations are concerned about the risks associated with products and services that may potentially contain malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the supply chain. These risks are associated with an enterprise’s decreased visibility into and understanding of how the technology they acquire is developed, integrated, and deployed or the processes, procedures, standards, and practices used to ensure the security, resilience, reliability, safety, integrity, and quality of the products and services. This publication provides guidance to organizations on identifying, assessing, and mitigating cybersecurity risks throughout the supply chain at all levels of their organizations. The publication integrates cybersecurity supply chain risk management (C-SCRM) into risk management activities by applying a multilevel, C-SCRM-specific approach, including guidance on the development of C-SCRM strategy implementation
Published: 2024-11-01
MHLW
Notice
MHLW-PFSB-MDED-0328-No.1
Guidance on Vulnerability Management to Ensure Cybersecurity of Medical Devices
PUBLISHED SBOM / Vulnerability
Notice on post-market vulnerability management framework. Requires manufacturers/distributors to integrate vulnerability monitoring, evaluation, response, and disclosure processes (including SBOM utilization) into quality management systems. Mandates establishment of PSIRT structure, clear vulnerability notification policies to customers, and practical end-of-life support management procedures.
Published: 2024-03-28
NIST
SP
SP 800-82 Rev. 3
Guide to Operational Technology (OT) Security
PUBLISHED NEW SBOM / Vulnerability
This document provides guidance on how to secure operational technology (OT) while addressing their unique performance, reliability, and safety requirements. OT encompasses a broad range of programmable systems and devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems and devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Examples include industrial control systems, building automation systems, transportation systems, physical access control systems, physical environment monitoring systems, and physical environment measurement systems. The document provides an overview of OT and typical system topologies, identifies common threats and vulnerabilities to these systems, and provides recommended security countermeasures to mitigate the associated risks.
Published: 2023-09-28
IMDRF
IMDRF/CYBER WG/N73 FINAL:2023
Principles and Practices for Software Bill of Materials for Medical Device Cybersecurity
PUBLISHED SBOM / Vulnerability
This document specifies IMDRF guidance on creating, managing, and sharing Software Bill of Materials (SBOM) for medical devices. It defines minimum SBOM elements, acceptable formats, and lifecycle management approaches necessary for effective cybersecurity management. Manufacturers should develop and maintain accurate SBOMs documenting all software components and dependencies throughout product lifecycle. The document provides the practical foundation for FDA 2023 final guidance SBOM submission requirements and supports implementation of Japan's vulnerability management notification requirements from the Ministry of Health, Labour and Welfare. SBOMs enable manufacturers, regulators, and healthcare organizations to identify and respond rapidly to software vulnerabilities affecting medical devices.
Published: 2023-04-13