ANSI TIR80001-2-2-2012 Application of risk management for IT-networks incorporating medical devices - Part 2-2 Guidance for the disclosure and communication of medical device secur.pdf
《ANSI TIR80001-2-2-2012 Application of risk management for IT-networks incorporating medical devices - Part 2-2 Guidance for the disclosure and communication of medical device secur.pdf》由会员分享,可在线阅读,更多相关《ANSI TIR80001-2-2-2012 Application of risk management for IT-networks incorporating medical devices - Part 2-2 Guidance for the disclosure and communication of medical device secur.pdf(68页珍藏版)》请在麦多课文档分享上搜索。
1、ANSI/AAMI/IEC TIR80001-2-2:2012Technical Information ReportApplication of risk management for IT-networks incorporating medical devices Part 2-2: Guidance for the disclosure and communication of medical device security needs, risks and controlsAn ANSI Technical Report prepared by AAMI ANSI/AAMI/IEC
2、TIR80001-2-2:2012 Application of risk management for IT-networks incorporating medical devices Part 2-2: Guidance for the disclosure and communication of medical device security needs, risks and controls Approved 20 August 2012 by Association for the Advancement of Medical Instrumentation Approved 3
3、0 September 2012 by American National Standards Institute, Inc. Abstract: Step-by-step guide to help in the application of risk management when creating or changing a medical IT-network. Keywords: medical device, risk management, information technology, interoperability, IT-network Published by Asso
4、ciation for the Advancement of Medical Instrumentation 4301 N. Fairfax Drive, Suite 301 Arlington, VA 22203-1633 www.aami.org 2012 by the Association for the Advancement of Medical Instrumentation All Rights Reserved This publication is subject to copyright claims of ISO, ANSI, and AAMI. No part of
5、this publication may be reproduced or distributed in any form, including an electronic retrieval system, without the prior written permission of AAMI. All requests pertaining to this document should be submitted to AAMI. It is illegal under federal law (17 U.S.C. 101, et seq.) to make copies of all
6、or any part of this document (whether internally or externally) without the prior written permission of the Association for the Advancement of Medical Instrumentation. Violators risk legal action, including civil and criminal penalties, and damages of $100,000 per offense. For permission regarding t
7、he use of all or any part of this document, complete the reprint request form at www.aami.org or contact AAMI, 4301 N. Fairfax Drive, Suite 301, Arlington, VA 22203-1633. Phone: +1-703-525-4890; Fax: +1-703-525-1067. Printed in the United States of America ISBN 1570204616 AAMI Technical Information
8、Report A technical information report (TIR) is a publication of the Association for the Advancement of Medical Instrumentation (AAMI) Standards Board that addresses a particular aspect of medical technology. Although the material presented in a TIR may need further evaluation by experts, releasing t
9、he information is valuable because the industry and the professions have an immediate need for it. A TIR differs markedly from a standard or recommended practice, and readers should understand the differences between these documents. Standards and recommended practices are subject to a formal proces
10、s of committee approval, public review, and resolution of all comments. This process of consensus is supervised by the AAMI Standards Board and, in the case of American National Standards, by the American National Standards Institute. A TIR is not subject to the same formal approval process as a sta
11、ndard. However, a TIR is approved for distribution by a technical committee and the AAMI Standards Board. Another difference is that, although both standards and TIRs are periodically reviewed, a standard must be acted onreaffirmed, revised, or withdrawnand the action formally approved usually every
12、 five years but at least every 10 years. For a TIR, AAMI consults with a technical committee about five years after the publication date (and periodically thereafter) for guidance on whether the document is still usefulthat is, to check that the information is relevant or of historical value. If the
13、 information is not useful, the TIR is removed from circulation. A TIR may be developed because it is more responsive to underlying safety or performance issues than a standard or recommended practice, or because achieving consensus is extremely difficult or unlikely. Unlike a standard, a TIR permit
14、s the inclusion of differing viewpoints on technical issues. CAUTION NOTICE: This AAMI TIR may be revised or withdrawn at any time. Because it addresses a rapidly evolving field or technology, readers are cautioned to ensure that they have also considered information that may be more recent than thi
15、s document. All standards, recommended practices, technical information reports, and other types of technical documents developed by AAMI are voluntary, and their application is solely within the discretion and professional judgment of the user of the document. Occasionally, voluntary technical docu
16、ments are adopted by government regulatory agencies or procurement authorities, in which case the adopting agency is responsible for enforcement of its rules and regulations. Comments on this technical information report are invited and should be sent to AAMI, Attn: Standards Department, 4301 N. Fai
17、rfax Drive, Suite 301, Arlington, VA 22203-1633. ANSI Technical Report This AAMI TIR has been registered by the American National Standards Institute as an ANSI Technical Report. Publication of this ANSI Technical Report has been approved by the accredited standards developer (AAMI). This document i
18、s registered as a Technical Report series of publications according to the Procedures for the Registration of Technical Reports with ANSI. This document is not an American National Standard and the material contained herein is not normative in nature. Comments on this technical information report ar
19、e invited and should be sent to AAMI, Attn: Standards Department, 4301 N. Fairfax Drive, Suite 301, Arlington, VA 22203-1633. Contents Page Glossary of equivalent standards vi Committee representation . ix Background of AAMI adoption of IEC/TR 80001-2-2:2012 . x FOREWORD xi INTRODUCTION xiii 1 Scope
20、 . 1 2 Normative references 2 3 Terms and definitions 2 4 Use of SECURITY CAPABILITIES 6 4.1 Structure of a SECURITY CAPABILITY entry 6 4.2 Guidance for use of SECURITY CAPABILITIES in the RISK MANAGEMENT PROCESS . 7 4.3 Relationship of ISO 14971-based RISK MANAGEMENT to IT security RISK MANAGEMENT
21、7 5 SECURITY CAPABILITIES . 8 5.1 Automatic logoff ALOF 8 5.2 Audit controls AUDT 9 5.3 Authorization AUTH 9 5.4 Configuration of security features CNFS . 11 5.5 Cyber security product upgrades CSUP 11 5.6 HEALTH DATA de-identification DIDT . 11 5.7 Data backup and disaster recovery DTBK . 12 5.8 Em
22、ergency access EMRG . 12 5.9 HEALTH DATA integrity and authenticity IGAU 13 5.10 Malware detection/protection MLDP 13 5.11 Node authentication NAUT 13 5.12 Person authentication PAUT 14 5.13 Physical locks on device PLOK . 15 5.14 Third-party components in product lifecycle roadmaps RDMP . 15 5.15 S
23、ystem and application hardening SAHD 16 5.16 Security guides SGUD 16 5.17 HEALTH DATA storage confidentiality STCF . 17 5.18 Transmission confidentiality TXCF 17 5.19 Transmission integrity TXIG 18 6 Example of detailed specification under SECURITY CAPABILITY: Person authentication PAUT 18 7 Referen
24、ces . 19 8 Other resources 21 8.1 General 21 8.2 Manufacture disclosure statement for medical device security (MDS2) . 21 8.3 Application security questionnaire (ASQ) . 21 8.4 The Certification Commission for Healthcare Information Technology (CCHIT) 21 8.5 http:/www.cchit.org/get_certifiedHL7 Funct
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ANSITIR80001222012APPLICATIONOFRISKMANAGEMENTFORITNETWORKSINCORPORATINGMEDICALDEVICESPART22GUIDANCEFORTHEDISCLOSUREANDCOMMUNICATIONOFMEDICALDEVICESECURPDF

链接地址:http://www.mydoc123.com/p-438753.html