• 0
    • ارسال درخواست
    • حذف همه
    • Industrial Standards
    • Defence Standards
  • درباره ما
  • درخواست موردی
  • فهرست استانداردها
    • Industrial Standards
    • Defence Standards
  • راهنما
  • Login
  • لیست خرید شما 0
    • ارسال درخواست
    • حذف همه
View Item 
  •   YSE
  • Industrial Standards
  • IEC - International Electrotechnical Commission
  • View Item
  •   YSE
  • Industrial Standards
  • IEC - International Electrotechnical Commission
  • View Item
  • All Fields
  • Title(or Doc Num)
  • Organization
  • Year
  • Subject
Advanced Search
JavaScript is disabled for your browser. Some features of this site may not work without it.

Archive

IEC TR 80001-2-9

English -- Application of risk management for it-networks incorporating medical devices - Part 2-9: Application guidance ? Guidance for use of security assurance cases to demonstrate confidence in IEC TR 80001-2-2 security capabilities - Edition 1.0

Organization:
IEC - International Electrotechnical Commission
Year: 2017

Abstract: Scope: This part of 80001 establishes a SECURITY CASE framework and provides guidance to health care delivery organizations (HDO) and MEDICAL DEVICE MANUFACTURERS (MDM) for identifying, developing, interpreting, updating and maintaining SECURITY CASES for networked MEDICAL DEVICES. Use of this part of 80001 is intended to be one of the possible means to bridge the gap between MDMs and HDOs in providing adequate information to support the HDOS RISK MANAGEMENT of IT-NETWORKS. This document leverages the requirements set out in ISO/IEC 15026-2 for the development of ASSURANCE cases2). It is not intended that this SECURITY CASE framework will replace a RISK MANAGEMENT strategy, rather, the intention is to complement RISK MANAGEMENT and in turn provide a greater level of ASSURANCE for a MEDICAL DEVICE by mapping specific RISK MANAGEMENT steps to each of the IEC TR 80001-2-2 SECURITY CAPABILITIES, identifying associated threats and vulnerabilities and presenting them in the format of a SECURITY CASE with the inclusion of a re-useable SECURITY PATTERN providing guidance for the selection of appropriate SECURITY CONTROLS to establish SECURITY CAPABILITIES and presenting them as part of the SECURITY CASE pattern (IEC TR 80001-2-8 provides examples of such SECURITY CONTROLS) providing EVIDENCE to support the implementation of a SECURITY CONTROL, hence providing CONFIDENCE in the establishment of each of the SECURITY CAPABILITIES The purpose of developing the SECURITY CASE is to demonstrate CONFIDENCE in the establishment of IEC TR 80001-2-2 SECURITY CAPABILITIES. The quality of artifacts gathered and documented during the development of the SECURITY CASE is agreed and documented as part of a RESPONSIBILITY AGREEMENT between the relevant stakeholders. This document provides guidance for one such methodology, through the use of a specific SECURITY PATTERN, to develop and interpret SECURITY CASES in a systematic manner
URI: http://yse.yabesh.ir/std;jsessiouthor:%22NAVY%20-%20YD%20-/handle/yse/235243
Collections :
  • IEC - International Electrotechnical Commission
  • Download PDF : (2.582Mb)
  • Show Full MetaData Hide Full MetaData
  • Statistics

    IEC TR 80001-2-9

Show full item record

contributor authorIEC - International Electrotechnical Commission
date accessioned2017-10-18T11:07:14Z
date available2017-10-18T11:07:14Z
date copyright2017.01.01
date issued2017
identifier otherUDVHUFAAAAAAAAAA.pdf
identifier urihttp://yse.yabesh.ir/std;jsessiouthor:%22NAVY%20-%20YD%20-/handle/yse/235243
description abstractScope: This part of 80001 establishes a SECURITY CASE framework and provides guidance to health care delivery organizations (HDO) and MEDICAL DEVICE MANUFACTURERS (MDM) for identifying, developing, interpreting, updating and maintaining SECURITY CASES for networked MEDICAL DEVICES. Use of this part of 80001 is intended to be one of the possible means to bridge the gap between MDMs and HDOs in providing adequate information to support the HDOS RISK MANAGEMENT of IT-NETWORKS. This document leverages the requirements set out in ISO/IEC 15026-2 for the development of ASSURANCE cases2). It is not intended that this SECURITY CASE framework will replace a RISK MANAGEMENT strategy, rather, the intention is to complement RISK MANAGEMENT and in turn provide a greater level of ASSURANCE for a MEDICAL DEVICE by mapping specific RISK MANAGEMENT steps to each of the IEC TR 80001-2-2 SECURITY CAPABILITIES, identifying associated threats and vulnerabilities and presenting them in the format of a SECURITY CASE with the inclusion of a re-useable SECURITY PATTERN providing guidance for the selection of appropriate SECURITY CONTROLS to establish SECURITY CAPABILITIES and presenting them as part of the SECURITY CASE pattern (IEC TR 80001-2-8 provides examples of such SECURITY CONTROLS) providing EVIDENCE to support the implementation of a SECURITY CONTROL, hence providing CONFIDENCE in the establishment of each of the SECURITY CAPABILITIES The purpose of developing the SECURITY CASE is to demonstrate CONFIDENCE in the establishment of IEC TR 80001-2-2 SECURITY CAPABILITIES. The quality of artifacts gathered and documented during the development of the SECURITY CASE is agreed and documented as part of a RESPONSIBILITY AGREEMENT between the relevant stakeholders. This document provides guidance for one such methodology, through the use of a specific SECURITY PATTERN, to develop and interpret SECURITY CASES in a systematic manner
languageEnglish
titleIEC TR 80001-2-9num
titleEnglish -- Application of risk management for it-networks incorporating medical devices - Part 2-9: Application guidance ? Guidance for use of security assurance cases to demonstrate confidence in IEC TR 80001-2-2 security capabilities - Edition 1.0en
typestandard
page40
statusActive
treeIEC - International Electrotechnical Commission:;2017
contenttypefulltext
DSpace software copyright © 2017-2020  DuraSpace
نرم افزار کتابخانه دیجیتال "دی اسپیس" فارسی شده توسط یابش برای کتابخانه های ایرانی | تماس با یابش
yabeshDSpacePersian
 
DSpace software copyright © 2017-2020  DuraSpace
نرم افزار کتابخانه دیجیتال "دی اسپیس" فارسی شده توسط یابش برای کتابخانه های ایرانی | تماس با یابش
yabeshDSpacePersian