FDA, DARPA Push Trustworthy Hardware

Share

FDA and Defense Advanced Research Projects Agency staffers said at a recent Silicon Flatiron event that hardware security and trust must involve the integration of hardware and software protection strategies, as well as resilient build practices. FDA cybersecurity policy advisor Jessica Wilkerson said the growing integration of hardware and software has led the agency to tighten security expectations for both, Government CIO reports in an online story.

“The system design, whether it’s a cybersecurity component, it’s a hardware component, whatever it is, it has to take into account the cybersecurity risks that could be faced and potentially mitigate for them,” Wilkerson said. “We need to be paying attention to the interplay between the hardware and some of the other components.”

She added that cybersecurity often focuses on the protection of the network and argued that with the advancing nature of hardware, engineers must build solutions that bake security controls into the devices themselves.

“Anywhere you can put on a security control, just put the security control on,” she said. “There are so many automated exploit kits out there…. It’s very difficult to protect against everything, but especially on the FDA side, the devices have to be protected…. Something is going to happen. There’s going to be a configuration error. There’s going to be an attack. Someone who’s going to deliberately try to screw with your systems — it’s not an if, it’s a when. Your system, to me, is not trustworthy unless you can weather whatever it is.”

Read more