Medical Device Security Offers Proving Ground for Cybersecurity Action

General News

Summary

In particular, the measure suggests a way to solve a conundrum at the center of cybersecurity policy: how to translate a general statutory or common law mandate to provide “reasonable” security into specific, technically sound controls. The programs’ continuation is a high priority for both industry and the FDA, so the bill is considered a must pass, making it an attractive vehicle for towing other policy initiatives across the legislative finish line. In the cybersecurity field, these tensions are acute, as the underlying technology of the information society rapidly changes (think of the lightening speed of the shift to cloud computing), as the threat evolves (exemplified by the rise of nation state attackers and the emergence of ransomware as a major problem for entities large and small), and as notions of what is minimally required expand (consider the elevation of multi-factor authentication). In deciding which of the recommended controls are necessary to “demonstrate a reasonable assurance of safety and effectiveness,” the FDA could look to the structure of the Security Rule adopted under the Health Insurance Portability and Accountability Act (HIPAA). In my view, the only way to build that system is sector-by-sector, relying on sector-specific agencies to do the kind of detailed work that the FDA has done in the new draft guidance on medical device cybersecurity—and then overseeing its implementation.

Classifications

industries
EduTech - institutions
applications
Engineering & Scientific

AskAI Classifications

Labels
No AI classifications detected

Linked Companies