Premarket Device Cybersecurity Efforts Fall Short: CDRH

Share

Medical device cybersecurity vulnerabilities are going to continue to evolve and emerge, and premarket controls are simply not sufficient to manage the threat throughout a device’s lifespan, CDRH associate director for science and strategic partnerships Suzanne Schwartz told a public workshop 1/20 in Silver spring, MD while announcing a new draft guidance on postmarketing recommendations. A guidance on premarket recommendations has been in effect since 2014.

 

“Acceptance of this new reality has not come easy for stakeholders within this sector, and it does require an attitudinal and culture shift,” she told the workshop “We all have to come to terms with this being the new normal.”

 

As proof premarket cybersecurity activities are lacking, CDRH recently conducted an assessment of 85 510(k)s submitted between 10/2014 and 10/2015 to determine whether there was a need for cybersecurity information in the submission and if any was provided. Schwartz said the findings showed that 69% (59 of 85) should have included cybersecurity information, and of these, 47% (28 of 59) did provide necessary information when needed. However, she said, 53% (31 of 59) did not provide cybersecurity information when needed.

 

Schwartz said the Center also reviewed 41 cybersecurity deficiencies contained in “additional information” request letters during the same time period. The review found that 32 of 41 (78%) of the deficiencies indicated that no cybersecurity information was provided in the file (including wireless security), and nine of 41 (22%) noted the submission contained cybersecurity information, but it was not sufficient.

 

“In looking at the deficiency issues for cybersecurity, our preliminary review reveals a significant learning curve here, and much work to be done for both industry and agency in delivering more rigor and more consistency with regard to submissions and the review process,” she said. The postmarketing guidance, she said, is premised on these key principles: 

  • Collaborative approach to information sharing and risk assessment 
  • Articulate manufacturer responsibilities by leveraging existing Quality System Regulation and postmarket authorities
  • Incentivize the “right” behavior
  • Risk-based approach to assuring risks to public health are addressed in a timely fashion 

According to Schwartz, cybersecurity risk management programs should include:   

  • Monitoring cybersecurity information sources for identification and detection of cybersecurity vulnerabilities and risk;
  • Understanding, assessing and detecting presence and impact of a vulnerability; 
  • Establishing and communicating processes for vulnerability intake and handling;
  • Clearly defining essential clinical performance to develop mitigations that protect, respond and recover from the cybersecurity risk;
  • Adopting a coordinated vulnerability disclosure policy and practice; and
  • Deploying mitigations that address cybersecurity risk early and prior to exploitation  

Additionally, Schwartz urged medical device makers to participate in an information sharing program run by an Information Sharing Analysis Organization (ISAO), a collaborative group where members share cybersecurity information. Under the program, device makers would receive useful and practical cybersecurity risk, threat indicator, and incident information via automated, real-time mechanisms if they choose to participate. She said participants in an ISAO can request that their information be treated as Protected Critical Infrastructure Information. “Such information is shielded from any release otherwise required by the Freedom of Information Act or state sunshine laws and is exempt from regulatory use and civil litigation,” she told the workshop.“Participating in information sharing activities will enhance this sector's maturity level, enabling better preparedness, as well as more timely remediation of vulnerabilities before exploit and harm.”

 

And going forward, Schwartz said FDA will focus on “development and validation of meaningful tools for assessment of vulnerabilities in the clinical environment. And as such, under a contract with Mitre we are seeking the development and validation of a common vulnerability scoring system that would enable, across the ecosystem, stakeholders to have a mechanism of identifying and assessing vulnerabilities.”

Read more