Standards, Guidance & Notices
Showing 91–100 of 146
NIST
FIPS
FIPS
FIPS 186-5
Digital Signature Standard (DSS)
This standard specifies a suite of algorithms that can be used to generate a digital signature. Digital signatures are used to detect unauthorized modifications to data and to authenticate the identity of the signatory. In addition, the recipient of signed data can use a digital signature as evidence in demonstrating to a third party that the signature was, in fact, generated by the claimed signatory. This is known as non-repudiation since the signatory cannot easily repudiate the signature at a later time.
Published: 2023-02-03
AAMI
TIR
TIR
AAMI TIR97:2019/(R)2023
Principles for medical device security — Postmarket risk management for device manufacturers
Technical information report providing guidance on postmarket security risk management for medical devices within the ISO 14971 safety risk management process. Designed for use with AAMI TIR57:2016. Covers PSIRT establishment, vulnerability disclosure policy, and coordinated vulnerability disclosure (CVD) frameworks. Closely aligned with FDA postmarket cybersecurity guidance. Published 2019, reaffirmed 2023.
Published: 2023-01-31
AAMI
TIR
TIR
AAMI TIR57:2016/(R)2023
Principles for medical device security — Risk management
Technical information report providing guidance on information security risk management for medical devices within the ISO 14971 safety risk management process. Incorporates expanded risk management concepts from IEC 62443, presenting practical methods for threat modeling and security risk assessment. Directly referenced by FDA's 2023 final cybersecurity guidance. Complementary to IEC 81001-5-1. Originally published 2016, reaffirmed 2023.
Published: 2023-01-13
JFMDA
Notice
Notice
jfmda_20221020_b84d0618
Handling of Software as a Medical Device (SaMD) Class I Products_October 20, 2022
Overview of handling procedures for SaMD Class I products. This document summarizes materials presented during the 2022 SaMD regulatory compliance seminar as an activity report by the SaMD Regulation Response Sub-Working Group.
Published: 2022-10-20
JFMDA
Notice
Notice
jfmda_20221020_fcd85f82
Explanatory Document for Software Medical Device Applicability Guideline - JFMDA Edition Version 1.0 October 20, 2022
JFMDA explanatory document providing detailed guidance on software medical device applicability determination and classification. Clarifies regulatory interpretation for software qualification and classification to support industry compliance and regulatory submissions.
Published: 2022-10-20
JFMDA
Notice
Notice
jfmda_20220601_faca0298
Establishment of Inquiry Contact Point for GS1-128 Reading Application for Medical Devices
As of June 1, 2022, the PMS Committee has published FAQs regarding GS1-128 barcode reading applications for medical devices. Frequently asked questions and responses are provided for reference.
Published: 2022-06-01
CEN/
CENELEC
CENELEC
EN ISO 14971:2019
Medical devices - Application of risk management to medical devices (ISO 14971:2019)
Regulation: MDR (EU) 2017/745 | Legislation: 2017/745 - Medical Devices | ESO: CEN | Amendments/Corrigenda: EN ISO 14971:2019/A11:2021 | Publication Decision: 2022/757 | Publication OJ: OJ L 138 | Start of legal effect: 17.05.2022
Published: 2022-05-17
IMDRF
IMDRF/AIMD WG/N67 (Edition 1)
Machine Learning-enabled Medical Devices: Key Terms and Definitions
Establishes a common vocabulary for machine learning used in medical devices. Defines key terms including model, training data, algorithm and performance evaluation measures, in order to promote a shared technical understanding and to facilitate regulatory communication across jurisdictions.
Published: 2022-05-09
NIST
SP
SP
SP 800-40 Rev. 4
Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology
Enterprise patch management is the process of identifying, prioritizing, acquiring, installing, and verifying the installation of patches, updates, and upgrades throughout an organization. Patching is more important than ever because of the increasing reliance on technology, but there is often a divide between business/mission owners and security/technology management about the value of patching. This publication frames patching as a critical component of preventive maintenance for computing technologies – a cost of doing business, and a necessary part of what organizations need to do in order to achieve their missions. This publication also discusses common factors that affect enterprise patch management and recommends creating an enterprise strategy to simplify and operationalize patching while also improving reduction of risk. Preventive maintenance through enterprise patch management helps prevent compromises, data breaches, operational disruptions, and other adverse events.
Published: 2022-04-06
JIS
Std
Std
JIS T 62366-1:2022
JIS T 62366-1:2022 Medical devices - Application of usability engineering to medical devices - Part 1: Design and evaluation (equivalent to IEC 62366-1:2015+Amd.1:2020)
This JIS standard specifies usability engineering processes for analyzing, specifying, developing, and evaluating safety-related human factors in medical devices, corresponding to IEC 62366-1:2015+Amendment 1:2020. The document establishes requirements for identifying and mitigating use errors that could result in harm to patients or operators, integrating human factors engineering into the device development lifecycle. Manufacturers must characterize the intended use environment, identify hazards associated with user interactions, develop mitigations through design and training, and conduct usability validation studies. The standard operates in conjunction with JIS T 14971 (risk management), as use-related risks must be identified and controlled through systematic usability engineering. The processes defined ensure that medical device designs accommodate user capabilities, limitations, and context of use to prevent foreseeable misuse. By systematically applying usability engineering principles, manufacturers reduce the likelihood of use errors and associated patient harm throughout the device lifecycle.
Published: 2022-03-25
