What is PD IEC/TR 80001-2-2 - Disclosure and communication of medical devices about?
PD IEC/TR 80001 is a European that discusses risk management for IT networks incorporating medical devices. PD IEC/TR 80001-2-2 provides a framework for the disclosure of security-related capabilities and risks necessary for managing the risk in connecting medical devices to IT networks and for the security dialogue that surrounds the IEC 80001-1 risk management of IT-network connection to minimise hazardous situations.
PD IEC/TR 80001-2-2 presents an informative set of common, high-level security-related capabilities useful in understanding the user needs, the type of security controls to be considered, and the risks that lead to the controls. Intended use and local factors determine which exact capabilities are useful in the dialogue about risk.
Note 1: PD IEC/TR 80001-2-2 does not contain sufficient detail for the exact specification of requirements in a request for proposal or product security disclosure sheet.
Note 2: The classification and structure can be used to organize such requirements with underlying detail sufficient for communication during the purchase and integration PROCESS for a MEDICAL DEVICE or IT equipment component.
Note 3: PD IEC/TR 80001-2-2 is intended to act as a basis for discussion and agreement sufficient to initial integration project risk management. Additionally, security only exists in the context of organisational security policies.
Note 4: The list under PD IEC/TR 80001-2-2 is not intended to constitute or support rigorous IT security standards-based controls and associated programs of certification and assurance such as might be found in other ISO standards.
Note5: Under PD IEC/TR 80001-2-2 security only exists in the context of the organizational security policies both the security policies of the healthcare delivery organization (HDO), and the product and services security policies of the MEDICAL DEVICE manufacturer (MDM) are outside the scope of PD IEC/TR 80001-2-2.
Who is PD IEC/TR 80001-2-2 - Disclosure and communication of medical devices for?
PD IEC/TR 80001-2-2 on disclosure and communication of medical devices is useful for:
- Health delivery organisations (HDOS)
- Medical device manufacturers (MDMS)
- IT vendors
Why should you use PD IEC/TR 80001-2-2 - Disclosure and communication of medical devices?
The security capabilities in PD IEC/TR 80001-2-2 provide a common, simple classification of security controls particularly suited to medical IT networks and the incorporated devices. PD IEC/TR 80001-2-2 guideline assists you with the use of security capabilities on the structure of a security capability entry, guidance for use of security capabilities in the risk management process, and relationship of ISO 14971 based risk management to its security risk management for the disclosure and communication of medical device security needs, risks, and controls.
PD IEC/TR 80001-2-2 guides on automatic logoff, audit controls, authorization, the configuration of security features, cyber security product upgrades, health data de-identification, emergency access, physical locks on the device, health data storage confidentiality, security, transmission integrity and more on security capabilities for the disclosure and communication of medical device security needs, risks, and controls.
PD IEC/TR 80001-2-2 also provides examples of detailed specifications under security capability, other resources, standards, and frameworks for the disclosure and communication of medical device security needs, risks, and controls.
With obedience and compliance to PD IEC/TR 80001-2-2, you can minimise the hazards to medical devices and enable proper risk management, security, and controls for the disclosure and communication of medical devices.