Draft Guidance Recommends Device Cybersecurity Actions
A new FDA draft guidance is intended to help medical device makers address postmarket management of cybersecurity vulnerabilities. The document outlines important steps they should take to continually address cybersecurity risks to keep patients safe and better protect the public health. It also details the agency’s recommendations for monitoring, identifying and addressing cybersecurity vulnerabilities in medical devices once they have entered the market.
“While manufacturers can incorporate controls in the design of a product to help prevent these risks, it is essential that manufacturers also consider improvements during maintenance of devices, as the evolving nature of cyber threats means risks may arise throughout a device’s entire lifecycle,” FDA says. The guidance also addresses the importance of information sharing via participation in an Information Sharing Analysis Organization (ISAO), a collaborative group where members share cybersecurity information. Additionally, it recommends that manufacturers “should implement a structured and systematic comprehensive cybersecurity risk management program and respond in a timely fashion to identified vulnerabilities.” Critical components of such a program should include:
- Applying the 2014 NIST voluntary Framework for Improving Critical Infrastructure Cybersecurity, which includes the core principles of “Identify, Protect, Detect, Respond and Recover;”
- Monitoring cybersecurity information sources for identification and detection of cybersecurity vulnerabilities and risk;
- Understanding, assessing and detecting presence and impact of a vulnerability;
- Establishing and communicating processes for vulnerability intake and handling;
- Clearly defining essential clinical performance to develop mitigations that protect, respond and recover from the cybersecurity risk;
- Adopting a coordinated vulnerability disclosure policy and practice; and
- Deploying mitigations that address cybersecurity risk early and prior to exploitation.
The guidance say that for the majority of cases, actions to address cybersecurity vulnerabilities and exploits are considered “cybersecurity routine updates or patches,” for which the agency does not require advance notification, additional premarket review or reporting under its regulations. “For a small subset of cybersecurity vulnerabilities and exploits that may compromise the essential clinical performance of a device and present a reasonable probability of serious adverse health consequences or death, the FDA would require medical device manufacturers to notify the agency.”
In situations where a vulnerability is quickly addressed, the agency says it does not intend to enforce urgent reporting of the vulnerability to the agency if certain conditions are met. These include:
- there are no serious adverse events or deaths associated with the vulnerability
- within 30 days after becoming aware of a vulnerability, the manufacturer notifies users and implements changes that reduce the risk to an acceptable level
- the manufacturer reports the vulnerability, its assessment and remediation to an ISAO.
The draft guidance is open for comments for the next 90 days. Additionally, FDA will hold a 1/20-21 public workshop, “Moving Forward: Collaborative Approaches to Medical Device Cybersecurity, to discuss the document further.