Standards, Guidance & Notices
Showing 111–120 of 146
NIST
SP
SP
SP 1800-24
Securing Picture Archiving and Communication System (PACS): Cybersecurity for the Healthcare Sector
Medical imaging plays an important role in diagnosing and treating patients. The system that manages medical images is known as the picture archiving communication system (PACS) and is nearly ubiquitous in healthcare environments. PACS is defined by the Food and Drug Administration (FDA) as a Class II device that “provides one or more capabilities relating to the acceptance, transfer, display, storage, and digital processing of medical images.” PACS centralizes functions surrounding medical imaging workflows and serves as an authoritative repository of medical image information.
PACS fits within a highly complex healthcare delivery organization (HDO) environment that involves interfacing with a range of interconnected systems. PACS may connect with clinical information systems and medical devices and engage with HDO-internal and affiliated health professionals. Complexity may introduce or expose opportunities that allow malicious actors to compromise the confidentiality, integrity, an
Published: 2020-12-21
NIST
IR
IR
IR 8259C
Creating a Profile Using the IoT Core Baseline and Non-Technical Baseline
The core baseline in NISTIR 8259A, IoT Device Cybersecurity Capability Core Baseline and the non-technical baseline in NISTIR 8259B, IoT Manufacturer Non-Technical Supporting Capability Core Baseline can be expanded upon based on more specific contextual information. Using source material with information pertinent to IoT device customers’ needs and goals, the central concepts of the NISTIR 8259 series can be used to guide the development of new elaboration on device cybersecurity capabilities an IoT device may need and the non-technical supporting capabilities that may be needed in relation to the IoT device. This process of expanding on the core baseline and non-technical baseline using additional contextual information is called profiling. A process by which readers of the NISTIR 8259 series can profile source documents is described in this publication.
Published: 2020-12-15
NIST
SP
SP
SP 800-53B
Control Baselines for Information Systems and Organizations
This publication provides security and privacy control baselines for the Federal Government. There are three security control baselines (one for each system impact level—low-impact, moderate-impact, and high-impact), as well as a privacy baseline that is applied to systems irrespective of impact level. In addition to the control baselines, this publication provides tailoring guidance and a set of working assumptions that help guide and inform the control selection process. Finally, this publication provides guidance on the development of overlays to facilitate control baseline customization for specific communities of interest, technologies, and environments of operation.
Published: 2020-12-10
NIST
SP
SP
SP 800-53 Rev. 5
Security and Privacy Controls for Information Systems and Organizations
This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk. The controls address diverse requirements derived from mission and business needs, laws, executive orders, directives, regulations, policies, standards, and guidelines. Finally, the consolidated control catalog addresses security and privacy from a functionality perspective (i.e., the strength of functions and mechanisms provided by the controls) and from an assurance perspective (i.e., the measure of confidence in the security or privacy capability provided by the controls). Addressing functionalit
Published: 2020-12-10
JIS
Std
Std
TR T 24971:2020
ISO/TR 24971:2020 Medical devices - Guidance on the application of ISO 14971
This technical report provides practical guidance on developing, implementing, and maintaining medical device risk management systems in accordance with JIS T 14971:2020 and its parent standard ISO 14971:2019. Published concurrently with JIS T 14971:2020 on October 1, 2020, the document offers detailed explanations and examples to support manufacturers in applying risk management principles effectively. The guidance clarifies the relationship between ISO 14971 requirements and other standards such as IEC 62304 and IEC 62366-1, demonstrating how risk management integrates with software lifecycle and usability engineering processes. Manufacturers should consult this technical report to understand implementation best practices, including hazard analysis methodologies, risk estimation approaches, risk control strategies, and residual risk evaluation techniques. The document addresses sector-specific considerations applicable to various medical device types and provides case studies demonstrating risk management in practice. This non-normative guidance helps organizations establish robust risk management culture and documentation while ensuring compliance with both Japanese regulatory requirements and international standards.
Published: 2020-10-01
JIS
Std
Std
JIS T 14971:2020
JIS T 14971:2020 Medical devices - Application of risk management to medical devices (equivalent to ISO 14971:2019)
This JIS standard specifies terminology, principles, and processes for applying risk management to medical devices, including Software as a Medical Device (SaMD) and In Vitro Diagnostic devices (IVD), corresponding to ISO 14971:2019. The 2020 revision strengthens provisions for addressing security risks and aligns terminology with JIS T 0063:2020 (vocabulary for medical device risk management). Manufacturers must establish and maintain a risk management system that identifies hazards, estimates risks, implements controls, and verifies their effectiveness throughout the device lifecycle. The standard provides a structured approach to ensure patient safety by reducing risks to acceptable levels. As the foundational risk management framework under Japanese medical device regulations, this standard works in conjunction with other lifecycle standards such as JIS T 2304 and JIS T 62366-1. The document replaced JIS T 14971:2003 and represents Japan's adoption of evolving international risk management best practices.
Published: 2020-10-01
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0831-No.14
Handling of Applications for Confirmation of Change Control Plans for Medical Devices
Foundational notification establishing Japan's IDATEN system (Improvement Design within Approval for Timely Evaluation and Notice). Defines the scope of eligible changes, application form requirements, supporting documentation, and notification procedures for implementing changes under a confirmed plan. Enables AI-enabled SaMD and other devices with anticipated post-market improvements to implement changes via minor change notification rather than full partial change approval.
Published: 2020-08-31
EU
MDCG
MDCG
MDCG 2019-16 rev.1
Guidance on cybersecurity for medical devices
MDCG 2019-16 rev.1 — Guidance on cybersecurity for medical devices — (July 2020)
Published: 2020-07-01
IEC
IEC 62366-1:2015+AMD1:2020
Medical devices — Part 1: Application of usability engineering to medical devices
Specifies a process for a manufacturer to analyse, specify, develop and evaluate the usability of a medical device as it relates to safety.
Published: 2020-06-01
ISO
ISO/TR 24971:2020
Medical devices — Guidance on the application of ISO 14971
Provides guidance on the application of ISO 14971:2019 for risk management of medical devices, including practical examples and clarifications.
Published: 2020-06-01
