UL 2900-2-1-2017 UL Standard for Safety Software Cybersecurity for Network-Connectable Products Part 2-1 Particular Requirements for Network Connectable Components of Healthcare anh.pdf
《UL 2900-2-1-2017 UL Standard for Safety Software Cybersecurity for Network-Connectable Products Part 2-1 Particular Requirements for Network Connectable Components of Healthcare anh.pdf》由会员分享,可在线阅读,更多相关《UL 2900-2-1-2017 UL Standard for Safety Software Cybersecurity for Network-Connectable Products Part 2-1 Particular Requirements for Network Connectable Components of Healthcare anh.pdf(21页珍藏版)》请在麦多课文档分享上搜索。
1、UL COPYRIGHTED MATERIAL NOT AUTHORIZED FOR FURTHER REPRODUCTION OR DISTRIBUTION WITHOUT PERMISSION FROM UL UL 2900-2-1 Software Cybersecurity for Network-Connectable Products, Part 2-1: Particular Requirements for Network Connectable Components of Healthcare and Wellness Systems, STANDARD FOR SAFETY
2、UL COPYRIGHTED MATERIAL NOT AUTHORIZED FOR FURTHER REPRODUCTION OR DISTRIBUTION WITHOUT PERMISSION FROM ULUL COPYRIGHTED MATERIAL NOT AUTHORIZED FOR FURTHER REPRODUCTION OR DISTRIBUTION WITHOUT PERMISSION FROM UL UL Standard for Safety for Software Cybersecurity for Network-Connectable Products, Par
3、t 2-1: Particular Requirements for Network Connectable Components of Healthcare and Wellness Systems, UL 2900-2-1 First Edition, Dated September 1, 2017 Summary of Topics This is the First Edition of the Standard for Software Cybersecurity for Network-Connectable Products, Part 2-1: Particular Requi
4、rements for Network Connectable Components of Healthcare and Wellness Systems, ANSI/UL 2900-2-1 All rights reserved. No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form by any means, electronic, mechanical photocopying, recording, or otherwise with
5、out prior permission of UL. UL provides this Standard as is without warranty of any kind, either expressed or implied, including but not limited to, the implied warranties of merchantability or tness for any purpose. In no event will UL be liable for any special, incidental, consequential, indirect
6、or similar damages, including loss of prots, lost savings, loss of data, or any other damages arising out of the use of or the inability to use this Standard, even if UL or an authorized UL representative has been advised of the possibility of such damage. In no event shall ULs liability for any dam
7、age ever exceed the price paid for this Standard, regardless of the form of the claim. Users of the electronic versions of ULs Standards for Safety agree to defend, indemnify, and hold UL harmless from and against any loss, expense, liability, damage, claim, or judgment (including reasonable attorne
8、ys fees) resulting from any error or deviation introduced while purchaser is storing an electronic Standard on the purchasers computer system. SEPTEMBER 1, 2017 UL 2900-2-1 tr1UL COPYRIGHTED MATERIAL NOT AUTHORIZED FOR FURTHER REPRODUCTION OR DISTRIBUTION WITHOUT PERMISSION FROM UL SEPTEMBER 1, 2017
9、 UL 2900-2-1 tr2 No Text on This PageUL COPYRIGHTED MATERIAL NOT AUTHORIZED FOR FURTHER REPRODUCTION OR DISTRIBUTION WITHOUT PERMISSION FROM UL SEPTEMBER 1, 2017 1 UL 2900-2-1 Software Cybersecurity for Network-Connectable Products, Part 2-1: Particular Requirements for Network Connectable Component
10、s of Healthcare and Wellness Systems, First Edition September 1, 2017 This ANSI/UL Standard for Safety consists of the First Edition. The most recent designation of ANSI/UL 2900-2-1 as an American National Standard (ANSI) occurred on September 1, 2017. ANSI approval for a standard does not include t
11、he Cover Page, Transmittal Pages, and Title Page. Comments or proposals for revisions on any part of the Standard may be submitted to UL at any time. Proposals should be submitted via a Proposal Request in ULs On-Line Collaborative Standards Development System (CSDS) at https:/. ULs Standards for Sa
12、fety are copyrighted by UL. Neither a printed nor electronic copy of a Standard should be altered in any way. All of ULs Standards and all copyrights, ownerships, and rights regarding those Standards shall remain the sole and exclusive property of UL. COPYRIGHT 2017 UNDERWRITERS LABORATORIES INC. AN
13、SI/UL 2900-2-1-2017UL COPYRIGHTED MATERIAL NOT AUTHORIZED FOR FURTHER REPRODUCTION OR DISTRIBUTION WITHOUT PERMISSION FROM UL SEPTEMBER 1, 2017 UL 2900-2-1 2 No Text on This PageUL COPYRIGHTED MATERIAL NOT AUTHORIZED FOR FURTHER REPRODUCTION OR DISTRIBUTION WITHOUT PERMISSION FROM UL CONTENTS INTROD
14、UCTION 1 Scope .4 2 Normative References .4 3 Glossary .5 DOCUMENTATION FOR PRODUCT, PROCESSES, AND USE 4 Product Documentation 5 5 Process Documentation5 6 Documentation for Product Use.5 6.1 Safety-related security considerations for product use.5 6.2 Instructions 6 SECURITY CONTROLS 7 General 6 8
15、 Access Control, User Authentication, and User Authorization .6 9 Remote Communication .6 10 Cryptography 6 11 Product Management.7 PRODUCT ASSESSMENT 12 Safety-Related Security Risk Management 7 12.1 Risk analysis7 12.2 Risk evaluation8 12.3 Risk control .8 12.4 Coverage of security analysis and te
16、sting 9 13 Known Vulnerability Testing 12 14 Malware Testing 12 15 Malformed Input Testing .12 16 Structured Penetration Testing .13 17 Software Weakness Analysis.14 18 Static Source Code Analysis 14 19 Static Binary and Bytecode Analysis 14 ORGANIZATIONAL ASSESSMENT 20 Lifecycle Security Processes
17、.14 20.1 Quality management processes 14 20.2 General procurement processes .14 20.3 Procurement risk management process .15 20.4 Product update release and patch management process 15 20.5 Decommissioning process .15 20.6 Packaging and shipment 16 SEPTEMBER 1, 2017 UL 2900-2-1 3UL COPYRIGHTED MATER
18、IAL NOT AUTHORIZED FOR FURTHER REPRODUCTION OR DISTRIBUTION WITHOUT PERMISSION FROM UL INTRODUCTION NOTE: This Standard for Software Cybersecurity for Network-Connectable Products, Part 2-1: Particular Requirements for Network Connectable Components of Healthcare and Wellness Systems, is to be used
19、in conjunction with the Standard for Software Cybersecurity for Network-Connectable Products, Part 1: General Requirements, UL 2900-1. The requirements for network connectable components of healthcare systems are contained in this part 2 standard and UL 2900-1. Requirements of this Part 2 standard,
20、where stated, amend the requirements of UL 2900-1. Where a particular subclause of UL 2900-1 is not mentioned in UL 2900-2-1, the UL 2900-1 subclause applies. 1 Scope 1.1 This security evaluation standard applies to the testing of network connected components of healthcare systems. It applies to, bu
21、t is not limited to, the following key components: a) Medical devices; b) Accessories to medical devices; c) Medical device data systems; d) In vitro diagnostic devices; e) Health information technology; and f) Wellness devices. 2 Normative References 2.1 The Standard for Software Cybersecurity for
22、Network-Connectable Products, Part 1: General Requirements, UL 2900-1, shall be applied as specied in this standard. 2.2 The Standard for Medical Devices Application of Risk Management to Medical Devices, ISO 14971:2007, shall be applied as specied in this standard. 2.3 The Standard for Medical Devi
23、ces Quality Management Systems Requirements for Regulatory Purposes, ISO 13485:2003, shall be applied as specied in this standard. 2.4 The Standard for Medical Device Software Software Life Cycle Processes, IEC 62304:2006, shall be applied as specied in this standard. SEPTEMBER 1, 2017 UL 2900-2-1 4
24、UL COPYRIGHTED MATERIAL NOT AUTHORIZED FOR FURTHER REPRODUCTION OR DISTRIBUTION WITHOUT PERMISSION FROM UL 3 Glossary 3.1 BASIC SAFETY Freedom from unacceptable risk, for those risks that are not directly related to the intended use of the product 3.2 ESSENTIAL PERFORMANCE Performance, other than th
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- UL2900212017ULSTANDARDFORSAFETYSOFTWARECYBERSECURITYFORNETWORKCONNECTABLEPRODUCTSPART21PARTICULARREQUIREMENTSFORNETWORKCONNECTABLECOMPONENTSOFHEALTHCAREANHPDF

链接地址:http://www.mydoc123.com/p-1068037.html