Five Areas to Address in Cybersecurity: Webinar

Share

An FDA 1/12 webinar on the agency’s final guidance on postmarket management of cybersecurity in medical devices says that addressing this issue means implementing a proactive comprehensive risk management program that incorporates several tenets: applying the NIST (National Institute of Standards and Technology) framework to strengthen critical infrastructure cyber security; establishing and communicating processes for vulnerability intake and handling; adopting a coordinated disclosure policy and practice; deploying mitigations that address security risk early and prior to exploitation; and engaging in collaborative information sharing for cyber vulnerabilities and threats.

Key principles, according to CDRH associate director for science and strategic partnerships Suzanne Schwartz, are using a risk-based framework to assure that public health risks are addressed in a continual and timely fashion, manufacturer responsibility as shown in existing quality system regulations and FDA’s post-market authority, fostering a collaborative and coordinated approach to information sharing and risk assessment, and maintaining close alignment with the executive orders and the guidance’s framework.

Read more