Standards, Guidance & Notices
Showing 101–110 of 146
NIST
SP
SP
SP 1800-30
Securing Telehealth Remote Patient Monitoring Ecosystem
Increasingly, healthcare delivery organizations (HDOs) are relying on telehealth and remote patient monitoring (RPM) capabilities to treat patients at home. RPM is convenient and cost-effective, and its adoption rate has increased. However, without adequate privacy and cybersecurity measures, unauthorized individuals may expose sensitive data or disrupt patient monitoring services.
RPM solutions engage multiple actors as participants in patients’ clinical care. These actors include HDOs, telehealth platform providers, and the patients themselves. Each participant uses, manages, and maintains different technology components within an interconnected ecosystem, and each is responsible for safeguarding their piece against unique threats and risks associated with RPM technologies.
This practice guide assumes that the HDO engages with a telehealth platform provider that is a separate entity from the HDO and patient. The telehealth platform provider manages a distinct infrastructure, applic
Published: 2022-02-22
NIST
SP
SP
SP 800-218
Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities
Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model to ensure that the software being developed is well-secured. This document recommends the Secure Software Development Framework (SSDF) – a core set of high-level secure software development practices that can be integrated into each SDLC implementation. Following these practices should help software producers reduce the number of vulnerabilities in released software, mitigate the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent future recurrences. Because the framework provides a common vocabulary for secure software development, software purchasers and consumers can also use it to foster communications with suppliers in acquisition processes and other management activities.
Published: 2022-02-03
NIST
SP
SP
SP 800-53A Rev. 5
Assessing Security and Privacy Controls in Information Systems and Organizations
This publication provides a methodology and set of procedures for conducting assessments of security and privacy controls employed within systems and organizations within an effective risk management framework. The assessment procedures, executed at various phases of the system development life cycle, are consistent with the security and privacy controls in NIST Special Publication 800-53, Revision 5. The procedures are customizable and can be easily tailored to provide organizations with the needed flexibility to conduct security and privacy control assessments that support organizational risk management processes and are aligned with the stated risk tolerance of the organization. Information on building effective security and privacy assessment plans is also provided with guidance on analyzing assessment results.
Published: 2022-01-25
CEN/
CENELEC
CENELEC
EN ISO 13485:2016
Medical devices - Quality management systems - Requirements for regulatory purposes (ISO 13485:2016)
Regulation: MDR (EU) 2017/745 | Legislation: 2017/745 - Medical Devices | ESO: CEN | Amendments/Corrigenda: EN ISO 13485:2016/AC:2018, EN ISO 13485:2016/A11:2021 | Publication Decision: 2022/6 | Publication OJ: OJ L 1 | Start of legal effect: 05.01.2022
Published: 2022-01-05
IEC
IEC 81001-5-1:2021
Health software and health IT systems safety, effectiveness and security — Part 5-1: Security — Activities in the product life cycle
Establishes a common framework for secure health software life cycle processes. Defines security activities and tasks to increase cybersecurity of health software.
Published: 2021-12-01
NIST
SP
SP
SP 800-213
IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements
Organizations will increasingly use Internet of Things (IoT) devices for the mission benefits they can offer, but care must be taken in the acquisition and implementation of IoT devices. This publication contains background and recommendations to help organizations consider how an IoT device they plan to acquire can integrate into a system. IoT devices and their support for security controls are presented in the context of organizational and system risk management. This publication provides guidance on considering system security from the device perspective. This allows for the identification of device cybersecurity requirements—the abilities and actions an organization will expect from an IoT device and its manufacturer and/or third parties, respectively.
Published: 2021-11-29
NIST
SP
SP
SP 800-213A
IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog
This publication provides a catalog of internet of things (IoT) device cybersecurity capabilities (i.e., features and functions needed from a device to support security controls) and non-technical supporting capabilities (i.e., actions and support needed from device manufacturers and other supporting entities to support security controls) that can help organizations as they use Special Publication (SP) 800-213 to determine and establish device cybersecurity requirements. This catalog cross references the capabilities in the catalog to the cybersecurity controls in NIST SP 800-53. Organizations should refer to SP 800-213 as that publication provides necessary context to effectively use this catalog and related material.
Published: 2021-11-29
EU
MDCG
MDCG
Helsinki Procedure
Helsinki Procedure for borderline and classification under MDR & IVDR
Helsinki Procedure — Helsinki Procedure for borderline and classification under MDR & IVDR — (September 2021)
Published: 2021-09-01
NIST
IR
IR
IR 8259B
IoT Non-Technical Supporting Capability Core Baseline
Non-technical supporting capabilities are actions a manufacturer or third-party organization performs in support of the cybersecurity of an IoT device. This publication defines an Internet of Things (IoT) device manufacturers’ non-technical supporting capability core baseline, which is a set of non-technical supporting capabilities generally needed from manufacturers or other third parties to support common cybersecurity controls that protect an organization’s devices as well as device data, systems, and ecosystems. The purpose of this publication is to provide organizations a starting point to use in identifying the non-technical supporting capabilities needed in relation to IoT devices they will manufacture, integrate, or acquire. This publication is intended to be used in conjunction with NISTIR 8259, Foundational Cybersecurity Activities for IoT Device Manufacturers and NISTIR 8259A, IoT Device Cybersecurity Capability Core Baseline.
Published: 2021-08-25
ISO
ISO 81001-1:2021
Health software and health IT systems safety, effectiveness and security — Part 1: Principles and concepts
⚠ NEWER VERSION
ISO 81001-1 Ed.2 - Health Software and Health IT Systems - Safety, Effectiveness and Security - Part 1: Principles and Concepts (2026-08-05) →
Provides principles, concepts, terms and definitions for health software and health IT systems, covering safety, effectiveness and security across the full life cycle.
Published: 2021-03-01
