Standards, Guidance & Notices
Showing 81–90 of 129
IMDRF
IMDRF/AIMD WG/N67 (Edition 1)
Machine Learning-enabled Medical Devices: Key Terms and Definitions
Edition 1 of the IMDRF Artificial Intelligence Medical Devices (AIMD) Working Group document on key terms and definitions for Machine Learning-enabled Medical Devices (MLMD). It establishes terms and definitions across the total product life cycle to promote consistency, support global harmonization, and provide a foundation for future guidelines on MLMD. Section 5 provides key definitions relevant to machine learning used in medical devices (including the definition of MLMD), Section 6 gives definitions from technical standards (e.g., bias, continuous learning, reference standard, reinforcement learning), and Section 7 discusses common machine learning terms. Most terms were previously defined in GHTF documents or internationally recognized AI standards, while some were developed or discussed by the AIMD Working Group. The document also notes that the term "bias" is used differently in data science and in legal discussions.
Published: 2022-05-09
NIST
SP
SP
SP 800-40 Rev. 4
Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology
Enterprise patch management is the process of identifying, prioritizing, acquiring, installing, and verifying the installation of patches, updates, and upgrades throughout an organization. Patching is more important than ever because of the increasing reliance on technology, but there is often a divide between business/mission owners and security/technology management about the value of patching. This publication frames patching as a critical component of preventive maintenance for computing technologies – a cost of doing business, and a necessary part of what organizations need to do in order to achieve their missions. This publication also discusses common factors that affect enterprise patch management and recommends creating an enterprise strategy to simplify and operationalize patching while also improving reduction of risk. Preventive maintenance through enterprise patch management helps prevent compromises, data breaches, operational disruptions, and other adverse events.
Published: 2022-04-06
JIS
Std
Std
JIS T 62366-1:2022
JIS T 62366-1:2022 Medical devices - Application of usability engineering to medical devices - Part 1: Design and evaluation (equivalent to IEC 62366-1:2015+Amd.1:2020)
This JIS standard specifies usability engineering processes for analyzing, specifying, developing, and evaluating safety-related human factors in medical devices, corresponding to IEC 62366-1:2015+Amendment 1:2020. The document establishes requirements for identifying and mitigating use errors that could result in harm to patients or operators, integrating human factors engineering into the device development lifecycle. Manufacturers must characterize the intended use environment, identify hazards associated with user interactions, develop mitigations through design and training, and conduct usability validation studies. The standard operates in conjunction with JIS T 14971 (risk management), as use-related risks must be identified and controlled through systematic usability engineering. The processes defined ensure that medical device designs accommodate user capabilities, limitations, and context of use to prevent foreseeable misuse. By systematically applying usability engineering principles, manufacturers reduce the likelihood of use errors and associated patient harm throughout the device lifecycle.
Published: 2022-03-25
NIST
SP
SP
SP 1800-30
Securing Telehealth Remote Patient Monitoring Ecosystem
Increasingly, healthcare delivery organizations (HDOs) are relying on telehealth and remote patient monitoring (RPM) capabilities to treat patients at home. RPM is convenient and cost-effective, and its adoption rate has increased. However, without adequate privacy and cybersecurity measures, unauthorized individuals may expose sensitive data or disrupt patient monitoring services.
RPM solutions engage multiple actors as participants in patients’ clinical care. These actors include HDOs, telehealth platform providers, and the patients themselves. Each participant uses, manages, and maintains different technology components within an interconnected ecosystem, and each is responsible for safeguarding their piece against unique threats and risks associated with RPM technologies.
This practice guide assumes that the HDO engages with a telehealth platform provider that is a separate entity from the HDO and patient. The telehealth platform provider manages a distinct infrastructure, applic
Published: 2022-02-22
NIST
SP
SP
SP 800-218
Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities
Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model to ensure that the software being developed is well-secured. This document recommends the Secure Software Development Framework (SSDF) – a core set of high-level secure software development practices that can be integrated into each SDLC implementation. Following these practices should help software producers reduce the number of vulnerabilities in released software, mitigate the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent future recurrences. Because the framework provides a common vocabulary for secure software development, software purchasers and consumers can also use it to foster communications with suppliers in acquisition processes and other management activities.
Published: 2022-02-03
NIST
SP
SP
SP 800-53A Rev. 5
Assessing Security and Privacy Controls in Information Systems and Organizations
This publication provides a methodology and set of procedures for conducting assessments of security and privacy controls employed within systems and organizations within an effective risk management framework. The assessment procedures, executed at various phases of the system development life cycle, are consistent with the security and privacy controls in NIST Special Publication 800-53, Revision 5. The procedures are customizable and can be easily tailored to provide organizations with the needed flexibility to conduct security and privacy control assessments that support organizational risk management processes and are aligned with the stated risk tolerance of the organization. Information on building effective security and privacy assessment plans is also provided with guidance on analyzing assessment results.
Published: 2022-01-25
CEN/
CENELEC
CENELEC
EN ISO 13485:2016/A11:2021
Medical devices - Quality management systems - Requirements for regulatory purposes (ISO 13485:2016)
Regulation: MDR (EU) 2017/745 | Legislation: 2017/745 - Medical Devices | ESO: CEN | Amendments/Corrigenda: EN ISO 13485:2016/AC:2018, EN ISO 13485:2016/A11:2021 | Publication Decision: 2022/6 | Publication OJ: OJ L 1 | Start of legal effect: 05.01.2022
Published: 2022-01-05
IEC
IEC 81001-5-1:2021
Health software and health IT systems safety, effectiveness and security — Part 5-1: Security — Activities in the product life cycle
Establishes a common framework for secure health software life cycle processes. Defines security activities and tasks to increase cybersecurity of health software.
Published: 2021-12-01
NIST
SP
SP
SP 800-213
IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements
Organizations will increasingly use Internet of Things (IoT) devices for the mission benefits they can offer, but care must be taken in the acquisition and implementation of IoT devices. This publication contains background and recommendations to help organizations consider how an IoT device they plan to acquire can integrate into a system. IoT devices and their support for security controls are presented in the context of organizational and system risk management. This publication provides guidance on considering system security from the device perspective. This allows for the identification of device cybersecurity requirements—the abilities and actions an organization will expect from an IoT device and its manufacturer and/or third parties, respectively.
Published: 2021-11-29
NIST
SP
SP
SP 800-213A
IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog
This publication provides a catalog of internet of things (IoT) device cybersecurity capabilities (i.e., features and functions needed from a device to support security controls) and non-technical supporting capabilities (i.e., actions and support needed from device manufacturers and other supporting entities to support security controls) that can help organizations as they use Special Publication (SP) 800-213 to determine and establish device cybersecurity requirements. This catalog cross references the capabilities in the catalog to the cybersecurity controls in NIST SP 800-53. Organizations should refer to SP 800-213 as that publication provides necessary context to effectively use this catalog and related material.
Published: 2021-11-29
