CDRH Endorses Device Cybersecurity Standard

Share

CDRH says it has recognized and supports industry’s use of a key consensus standard to support device sponsors in their cybersecurity efforts. The standard in entitled “ANSI/AAMI SW96:2023 Standard for medical device security —- Security risk management for device manufacturers.” The Center says it “aligns with existing international safety risk management standards and quality systems expectations, and provides direction to sponsors on how to consider and address cybersecurity risks in device design and development.”

The standard is intended to provide requirements and guidance when addressing design, production and post-production security risk management for devices within the risk management framework defined by ISO 14971, according to the agency. It assists manufacturers with identifying threats, vulnerabilities, and assets associated with medical devices and their components and supply chain vendors. It also helps firms determine appropriate security risk controls to reduce security risks, and then verify and monitor the effectiveness of the security risk controls.

Read more