BS PD IEC TR 80001-2-8-2016 Application of risk management for IT-networks incorporating medical devices Application guidance Guidance on standards for establishing the security ca.pdf
《BS PD IEC TR 80001-2-8-2016 Application of risk management for IT-networks incorporating medical devices Application guidance Guidance on standards for establishing the security ca.pdf》由会员分享,可在线阅读,更多相关《BS PD IEC TR 80001-2-8-2016 Application of risk management for IT-networks incorporating medical devices Application guidance Guidance on standards for establishing the security ca.pdf(56页珍藏版)》请在麦多课文档分享上搜索。
1、Application of risk managementfor IT-networks incorporatingmedical devicesPart 2-8: Application guidance Guidance on standards for establishing the security capabilities identified in IEC TR 80001-2-2PD IEC/TR 80001-2-8:2016BSI Standards PublicationNational forewordThis Published Document is the UK
2、implementation of IEC/TR80001-2-8:2016.The UK participation in its preparation was entrusted by TechnicalCommittee CH/62, Electrical Equipment in Medical Practice, toSubcommittee CH/62/1, Common aspects of Electrical Equipment used inMedical Practice.A list of organizations represented on this commi
3、ttee can be obtained onrequest to its secretary.This publication does not purport to include all the necessary provisions ofa contract. Users are responsible for its correct application. The British Standards Institution 2016.Published by BSI Standards Limited 2016ISBN 978 0 580 87358 4ICS 11.040.01
4、Compliance with a British Standard cannot confer immunity fromlegal obligations.This Published Document was published under the authority of theStandards Policy and Strategy Committee on 31 May 2016.Amendments/corrigenda issued since publicationDate Text affectedPUBLISHED DOCUMENTPD IEC/TR 80001-2-8
5、:2016IEC TR 80001-2-8 Edition 1.0 2016-05 TECHNICAL REPORT Application of risk management for IT-networks incorporating medical devices Part 2-8: Application guidance Guidance on standards for establishing the security capabilities identified in IEC TR 80001-2-2 INTERNATIONAL ELECTROTECHNICAL COMMIS
6、SION ICS 11.040.01 ISBN 978-2-8322-3412-9 Warning! Make sure that you obtained this publication from an authorized distributor. PD IEC/TR 80001-2-8:2016 2 IEC TR 80001-2-8:2016 IEC 2016 CONTENTS FOREWORD . 4 INTRODUCTION . 6 1 Scope 9 2 Normative references. 9 3 Terms and definitions 10 4 Guidance f
7、or establishing SECURITY CAPABILITIES 13 4.1 General . 13 4.2 Automatic logoff ALOF . 14 4.3 Audit controls AUDT . 15 4.4 Authorization AUTH 17 4.5 Configuration of security features CNFS . 19 4.6 Cyber security product upgrades CSUP 21 4.7 HEALTH DATA de-identification DIDT . 24 4.8 Data backup and
8、 disaster recovery DTBK . 25 4.9 Emergency access EMRG 27 4.10 HEALTH DATA integrity and authenticity IGAU . 28 4.11 Malware detection/protection MLDP 30 4.12 Node authentication NAUT . 32 4.13 Person authentication PAUT . 35 4.14 Physical locks on device PLOK . 37 4.15 Third-party components in pro
9、duct lifecycle roadmaps RDMP 39 4.16 System and application hardening SAHD 42 4.17 Security guides SGUD 44 4.18 HEALTH DATA storage confidentiality STCF . 47 4.19 Transmission confidentiality TXCF 48 4.20 Transmission integrity TXIG 50 Bibliography . 51 Table 1 ALOF controls . 14 Table 2 AUDT contro
10、ls . 16 Table 3 AUTH controls . 18 Table 4 CNFS controls . 20 Table 5 CSUP controls . 22 Table 6 DIDT controls 24 Table 7 DTBK controls . 26 Table 8 EMRG controls 28 Table 9 IGAU controls 29 Table 10 MLDP controls . 30 Table 11 NAUT controls . 33 Table 12 PAUT controls . 36 Table 13 PLOK controls .
11、38 Table 14 RDMP controls 40 Table 15 SAHD controls . 43 PD IEC/TR 80001-2-8:2016IEC TR 80001-2-8:2016 IEC 2016 3 Table 16 SGUD controls. 45 Table 17 STCF controls . 48 Table 18 TXCF controls . 49 Table 19 TXIG controls 50 PD IEC/TR 80001-2-8:2016 4 IEC TR 80001-2-8:2016 IEC 2016 INTERNATIONAL ELECT
12、ROTECHNICAL COMMISSION _ APPLICATION OF RISK MANAGEMENT FOR IT-NETWORKS INCORPORATING MEDICAL DEVICES Part 2-8: Application guidance Guidance on standards for establishing the security capabilities identified in IEC TR 80001-2-2 FOREWORD 1) The International Electrotechnical Commission (IEC) is a wo
13、rldwide organization for standardization comprising all national electrotechnical committees (IEC National Committees). The object of IEC is to promote international co-operation on all questions concerning standardization in the electrical and electronic fields. To this end and in addition to other
14、 activities, IEC publishes International Standards, Technical Specifications, Technical Reports, Publicly Available Specifications (PAS) and Guides (hereafter referred to as “IEC Publication(s)”). Their preparation is entrusted to technical committees; any IEC National Committee interested in the su
15、bject dealt with may participate in this preparatory work. International, governmental and non-governmental organizations liaising with the IEC also participate in this preparation. IEC collaborates closely with the International Organization for Standardization (ISO) in accordance with conditions d
16、etermined by agreement between the two organizations. 2) The formal decisions or agreements of IEC on technical matters express, as nearly as possible, an international consensus of opinion on the relevant subjects since each technical committee has representation from all interested IEC National Co
17、mmittees. 3) IEC Publications have the form of recommendations for international use and are accepted by IEC National Committees in that sense. While all reasonable efforts are made to ensure that the technical content of IEC Publications is accurate, IEC cannot be held responsible for the way in wh
18、ich they are used or for any misinterpretation by any end user. 4) In order to promote international uniformity, IEC National Committees undertake to apply IEC Publications transparently to the maximum extent possible in their national and regional publications. Any divergence between any IEC Public
19、ation and the corresponding national or regional publication shall be clearly indicated in the latter. 5) IEC itself does not provide any attestation of conformity. Independent certification bodies provide conformity assessment services and, in some areas, access to IEC marks of conformity. IEC is n
20、ot responsible for any services carried out by independent certification bodies. 6) All users should ensure that they have the latest edition of this publication. 7) No liability shall attach to IEC or its directors, employees, servants or agents including individual experts and members of its techn
21、ical committees and IEC National Committees for any personal injury, property damage or other damage of any nature whatsoever, whether direct or indirect, or for costs (including legal fees) and expenses arising out of the publication, use of, or reliance upon, this IEC Publication or any other IEC
22、Publications. 8) Attention is drawn to the Normative references cited in this publication. Use of the referenced publications is indispensable for the correct application of this publication. 9) Attention is drawn to the possibility that some of the elements of this IEC Publication may be the subjec
23、t of patent rights. IEC shall not be held responsible for identifying any or all such patent rights. The main task of IEC technical committees is to prepare International Standards. However, a technical committee may propose the publication of a technical report when it has collected data of a diffe
24、rent kind from that which is normally published as an International Standard, for example “state of the art“. IEC 80001-2-8, which is a technical report, has been prepared by subcommittee 62A: Common aspects of electrical equipment used in medical practice, of IEC technical committee 62: Electrical
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSPDIECTR80001282016APPLICATIONOFRISKMANAGEMENTFORITNETWORKSINCORPORATINGMEDICALDEVICESAPPLICATIONGUIDANCEGUIDANCEONSTANDARDSFORESTABLISHINGTHESECURITYCAPDF

链接地址:http://www.mydoc123.com/p-588945.html