Integrated Security, Safety, and Privacy Risk Assessment Framework for Medical Devices

被引:15
|
作者
Yaqoob, Tahreem [1 ]
Abbas, Haider [1 ]
Shafqat, Narmeen [1 ]
机构
[1] Natl Univ Sci & Technol NUST, Islamabad 44000, Pakistan
关键词
Medical devices; Security; Safety; Standards; Risk management; Privacy; Europe; ISSP risk assessment framework; CVSS; FDA; EU; Bayesian theorem;
D O I
10.1109/JBHI.2019.2952906
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The substantial improvements and innovations in communication networks and bio-medical technologies have led to the adoption of networked medical devices due to which the attack surface has increased profoundly. Numerous devices in practice were designed and developed years ago without security measures. In such a scenario, the role of regulatory bodies has become evident. The Food and Drug Administration (FDA) validates and approves devices before commercialization. In contrast, the European Union (EU) follows a decentralized approach and Notified Bodies (NB) for assuring high standards, safety and quality of medical devices being marketed in Europe. Once the device has gone through stringent regulations including good manufacturing practices, Quality Management System (QMS), labeling, clinical tests, performance standards, adequate storage and packaging practices, a declaration of conformity will be granted, which is a legal binding document stating that the device is conformant with applicable European requirements and can be marketed in Europe. However, such regulations lack a systematic methodology to determine unified security, safety and privacy risk that eventually influence the health of patients. To cover these gaps, this research proposes Integrated Safety, Security, and Privacy (ISSP) Risk Assessment Framework to determine the risk level of the device and required security controls. It is, then applied to a case scenario of an infusion pump and further evaluated by comparing it with current standards and practices. The comparison shows that the framework provides a unified approach to consider different types of risks associated with devices.
引用
收藏
页码:1752 / 1761
页数:10
相关论文
共 50 条
  • [1] Integrated Safety and Risk Assessment for Medical Devices and Combination Products
    Traul, Karl A.
    [J]. INTERNATIONAL JOURNAL OF TOXICOLOGY, 2020, 39 (04) : 354 - 355
  • [2] Security and privacy for implantable medical devices
    Halperin, Daniel
    Kohno, Tadayoshi
    Heydt-Benjamin, Thomas S.
    Fu, Kevin
    Maisel, William H.
    [J]. IEEE PERVASIVE COMPUTING, 2008, 7 (01) : 30 - 39
  • [3] Security and Privacy in the Internet of Medical Things: Taxonomy and Risk Assessment
    Alsubaei, Faisal
    Shiva, Sajjan
    Abuhussein, Abdullah
    [J]. 2017 IEEE 42ND CONFERENCE ON LOCAL COMPUTER NETWORKS WORKSHOPS (LCN WORKSHOPS 2017), 2017, : 112 - 120
  • [4] Towards Integrated Quantitative Security and Safety Risk Assessment
    Dobaj, Juergen
    Schmittner, Christoph
    Krisper, Michael
    Macher, Georg
    [J]. COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2019, 2019, 11699 : 102 - 116
  • [5] Risk Assessment Method for Balancing Safety, Security, and Privacy in Medical IoT Systems with Remote Maintenance Function
    Sasaki, Ryoichi
    [J]. COMPANION OF THE 2020 IEEE 20TH INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY, AND SECURITY (QRS-C 2020), 2020, : 190 - 197
  • [6] Safety and Security Architecture Analyses Framework for the Internet of Things of Medical Devices
    Rauscher, Julia
    Bauer, Bernhard
    [J]. 2018 IEEE 20TH INTERNATIONAL CONFERENCE ON E-HEALTH NETWORKING, APPLICATIONS AND SERVICES (HEALTHCOM), 2018,
  • [7] The Security and Privacy Protection Framework for Wearable Devices
    Cui, Youxiang
    Gu, Zhongwei
    Sun, Lei
    Tang, Haibo
    Cui, Lumeng
    [J]. DESIGN, OPERATION AND EVALUATION OF MOBILE COMMUNICATIONS, MOBILE 2022, 2022, 13337 : 203 - 210
  • [8] Human factors risk assessment: An integrated method for improving safety in clinical use of medical devices
    Song, Wenyan
    Li, Jing
    Li, Hao
    Ming, Xinguo
    [J]. APPLIED SOFT COMPUTING, 2020, 86
  • [9] Security and safety for medical devices and hospitals
    Baker, Steven D.
    Knudsen, Jonathan
    Ahmadi, D. Mike
    [J]. Biomedical Instrumentation and Technology, 2013, 47 (03): : 208 - 211
  • [10] SPE: Security and Privacy Enhancement Framework for Mobile Devices
    Krupp, Brian
    Sridhar, Nigamanth
    Zhao, Wenbing
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2017, 14 (04) : 433 - 446