Revised Guide on Device Premarket Cybersecurity Soon

Share

CDRH expects to release by the end of the year an updated draft guidance on medical device cybersecurity premarket submission recommendations. Speaking at a 5/13 FDA/Xavier MedCon conference, CDRH cybersecurity policy analyst Matthew Hazelett said the 2018-released draft on Content of Premarket Submissions for Management of Cybersecurity in Medical Devices is being revised based on public comments received to date. It will recommend that device makers “focus on making sure that cybersecurity is designed into the device and the consideration for the maintenance of cybersecurity over time.” The document will also be based on a “secure product development framework and making sure that cybersecurity is built in from the beginning,” he told the conference.


Comments submitted by AdvaMed on the earlier draft guidance said (1) FDA should eliminate the proposed two-tier risk approach; (2) FDA should explain its authority over the cybersecurity bill of materials and what its expectation is for how often a manufacturer would be expected to update the bill of materials; (3) the proposed labeling recommendations should focus on product communications; (4) FDA should explain its plan for implementing the draft guidance; and (5) the agency should address forensic design elements and account for diversity in device design.


When FDA released the 2018 guidance, then-FDA commissioner Scott Gottlieb touted in an online posit the “utility of providing customers and users with a ‘cybersecurity bill of materials’ – a list of commercial or off-the-shelf software and hardware components of a device that could be susceptible to vulnerabilities.  Depending on the level of cybersecurity risk associated with a device, this list can be an important resource to help ensure that device customers and users are able to respond quickly to potential threats.”


Hazelett said CDRH’s cybersecurity central review area is risk management, which looks into how firms identified the different risks and mitigations from a cybersecurity perspective. “So this includes things like threat modeling assessment of vulnerabilities from any third-party software in the device, that includes commercial off-the-shelf software and open-source software,” he said. The Center also looks at cybersecurity risk assessments, such as determinations about the acceptability of risk based on cybersecurity harm.


“So we look at the severity of the patient harm and ... how easy it is to exploit some of these potential risks,” Hazelett continued. “We also apply special focus on looking for things that can have multi-patient risks, so if your device relies on network connectivity, what is the impact on patient care, if all of those connections go down?”


Regarding monitoring capability, Hazelett said CDRH looks at how a firm is tying in complaints, how it assesses vulnerabilities from third-party software, as well as how it is able to update and release and deploy patches. Additionally, FDA looks at how device makers address malware-free shipping by looking at how they control and ensure that malware was not introduced prior to shipment or during update processes. “This also looks at software updates and delivery mechanisms to make sure that the software that's being updated cannot be impacted or intercepted or maliciously tampered with,” he told the conference.


Additionally, labeling is a big area of growing focus, Hazelett said, adding that instructions to ensure a safe and effective use of the device should also address security controls as well as informing device users about the connectivity of the device, the available interfaces and what instructions they need to be able to follow in order to basically operate the device and maintain it when patches become available. CDRH also looks at the manufacturer disclosure statement for medical device security and the software bill of materials, if provided to customers, because these are useful in verifying completeness of certain assessments, he said.

 

Read more