政府机构致力于保护输液泵对抗网络威胁
发布日期:2015/1/22 点击数:665新闻来源:FDA

引用涉及医疗设备的新的风险和漏洞,美国国家标准与技术研究所(NIST)内的一个中心正寻求公众反馈意见的文件草案,探讨如何解决关于无线输液泵的网络安全挑战。

卓越国家网络安全中心(NCCoE),与明尼苏达大学的科技领导研究院合作,提出该文件是对于确定无线安全解决方案巨大努力的的一部分。最终的结果将是一个NIST网络安全实践指南。

这是卓越的国家网络安全中心第一医疗设备项目,和我们的第二个重点医疗部门,” NCCoE的副主任Nate Lesse在一份预声明中说。与科技领导研究院和医疗器械社区合作,帮助了我们确定这个挑战,我们期待继续合作。

文件列出了对输液泵有影响的参与者,包括生物医学工程师,患者,以及任何企图做出损害行为的未经授权用户。该文件也向公司高层提出了在医疗界的威胁和漏洞,同时也提供了对于可以用来减轻这些风险的广泛的技术的理解。

虽然草案是朝正确方向迈出的一步,一些利益相关者表示有些保留,特别是由于NIST缺乏政府监管。无论他们想出什么都是不能满足我们的需要的,根据安全咨询公司CynergisTek首席执行官,MAC麦克米伦所说。我们需要的是食品和药物管理局提出了一个硬性的规则,[制造商]要注意的。

文件草案的发布是在同一天,奥巴马总统签署了网络安全加强法案s.1353 2014法。它规范了NIST在支持“自发的,一致的,行业带头的标准和成本节约的降低网络风险的关键基础设施程序的发展。

NIST不是唯一的致力于防止网络医疗设备受到网络攻击的联邦机构。去年十月,美国食品和药品管理局和国土安全部举行了为期两天的研讨会,会上,参与者商议行业和政府可以共同打击网络威胁。会议结束大约三周后FDA公布最后的对医疗器械上市前对网络安全的考虑提交的指导性文件。


 

 

Agency Aims to Guard Infusion Pumps against Cyberthreats

Citing new risks and vulnerabilities involving medical devices, a center within the National Institute of Standards and Technology (NIST) is seeking public feedback on a draft document that examines how to address cybersecurity challenges related to wireless infusion pumps.

NIST’s National Cybersecurity Center of Excellence (NCCoE), in cooperation with the Technological Leadership Institute at the University of Minnesota, says the document is part of a larger effort to identify solutions for wireless security. The end result will be a NIST Cybersecurity Practice Guide.

“This is the first medical device project for the National Cybersecurity Center of Excellence, and our second focused on the healthcare sector,” said Nate Lesser, deputy director of the NCCoE, in a prepared statement. “Working with the Technological Leadership Institute and the medical device community helped us identify this challenge and we look forward to continued collaboration."

The document names the actors who could interact with the infusion pump, including the biomedical engineer, patient, and any unauthorized user intent on doing harm. It also “provides executives with threats and vulnerabilities in the healthcare community and an understanding of the wide array of technologies that can be employed to mitigate these risks,” according to the document.


While the draft document is viewed as a step in the right direction, some stakeholders have expressed some reservations, particularly since NIST lacks regulatory oversight, as Gov Info Security notes. "Whatever they come up with is not going to get us where we need to go," according to Mac McMillan, chief executive of security consulting firm CynergisTek, as cited by the website. "What we need is for the Food and Drug Administration to put out a hard and fast rule that [manufacturers] have to pay attention to.”

The release of the draft document came the same day President Obama signed S.1353 - Cybersecurity Enhancement Act of 2014 in to law. It formalizes NIST’s role in supporting the development of “a voluntary, consensus-based, industry-led set of standards and procedures to cost-effectively reduce cyber risks to critical infrastructure.”

NIST is not the only federal body working to prevent cyberattacks against networked medical devices. Last October, the U.S. Food and Drug Administration and Department of Homeland Security held a two-day workshop, during which participants discussed ways industry and government can work together to combat cyberthreats. The workshop came roughly three weeks after the FDA released a final guidance document on cybersecurity considerations for premarket submissions for medical devices.

上一条:2015年全国医疗器械监督管理工作会议在京召开   下一条:医疗设备生产商参与医疗设备单审核程序试点(MDSAP)
关于我们|联系我们|会员登录|会员注册|忘记密码
  版权所有:中国医疗器械行业协会医用高分子制品专业分会  www.cncamda.org
电话:010-68330336  邮政编码:100036  地址:北京市海淀区复兴路17号国海广场D座2109
未经书面许可严禁转载和复制本站的任何信息  目前您是第4355220位