Skip to main content

Framework to Assist Healthcare Delivery Organisations and Medical Device Manufacturers Establish Security Assurance for Networked Medical Devices

  • Conference paper
Systems, Software and Services Process Improvement (EuroSPI 2013)

Part of the book series: Communications in Computer and Information Science ((CCIS,volume 364))

Included in the following conference series:

Abstract

This paper introduces an assurance framework for networked medical device development. This work is being conducted to address the ever-increasing concerns of medical device security with a specific focus on medical devices to be incorporated into IT networks. The framework utilises a Process Assessment Model and a Process Reference Model to address system development lifecycle processes, security assurance processes and a focused risk management process. There is currently no governance for the development of secure medical devices in place and so, this work sets out to resolve this problem by increasing the awareness of medical device security risks, threats and vulnerabilities among Medical Device Manufacturers, IT vendors and Healthcare Delivery Organisations.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. ISO/IEC, 15504-2: 2003 Software Engineering - Process Assessment - Performing an Assessment (2003)

    Google Scholar 

  2. SEI, CMMI-DEV, CMMI for Development (2010)

    Google Scholar 

  3. ISO/IEC, 15504-6:2008 Information technology — Process assessment — An exemplar system life cycle process assessment model (2008)

    Google Scholar 

  4. Finnegan, A., McCaffery, F., Coleman, G.: Development of a process assessment model for assessing security of IT networks incorporating medical devices against ISO/IEC 15026-4. In: Healthinf 2013, Barcelona, Spain, pp. 250–255 (2013)

    Google Scholar 

  5. DHS, Attack Surface: Healthcare and Public Heath Sector (2012)

    Google Scholar 

  6. Rashid, F.Y.: Researchers Uncover Privilege Escalation Bug in Philips Medical Devices (2013), http://www.securityweek.com

  7. GAO, Medical Devices, FDA Should Expland Its Consideration of Information Security for Certain Types of Devices (2012)

    Google Scholar 

  8. ISO/IEC, 15288 - Systems engineering — System life cycle processes (2008)

    Google Scholar 

  9. ISO/IEC, 15026-4: Systems and Software Engineering - Systems and Software Assurance - Assurance in the Life Cycle (2012)

    Google Scholar 

  10. IEC, TR 80001-2-2 - Application of risk management for IT-networks incorporating medical devices - Guidance for the disclosure and communication of medical device security needs, risks and control, International Electrotechnical Committee (2011)

    Google Scholar 

  11. ISO/IEC, 27001 Information Technology - Security Techniques - Information Security Management Systems - Requirements (2005)

    Google Scholar 

  12. ISO, EN ISO 27799:2008 Health informatics. Information security management in health using ISO/IEC 27002 (2008)

    Google Scholar 

  13. ISO/IEC, 15408-1 Information Technology - Security Techniques - Evaluation Criteria for IT Security, in Introduction and General Model (2009)

    Google Scholar 

  14. IEC, 62443-3-3 – Security for industrial automation and control systems - Network and system security – System security requirements and security assurance levels Introductory Note (2011)

    Google Scholar 

  15. NIST, 800-53 Recommended Security Controls for Federal Information Systems and Organisations, U.S.D.o. Commerce, Editor (2009)

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2013 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Finnegan, A., McCaffery, F., Coleman, G. (2013). Framework to Assist Healthcare Delivery Organisations and Medical Device Manufacturers Establish Security Assurance for Networked Medical Devices. In: McCaffery, F., O’Connor, R.V., Messnarz, R. (eds) Systems, Software and Services Process Improvement. EuroSPI 2013. Communications in Computer and Information Science, vol 364. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-39179-8_28

Download citation

  • DOI: https://doi.org/10.1007/978-3-642-39179-8_28

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-642-39178-1

  • Online ISBN: 978-3-642-39179-8

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics