SlideShare a Scribd company logo
1
AAMI TIR 57 Bi-dimensional Risk Analysis
Security and safety design
Antonio Bartolozzi
antonio.bartolozzi@bartolozzi.it 25/11/2019
2antonio.bartolozzi@bartolozzi.it
Electronic programmable systems – Essential principles of
safety and performance
state of the art
use harmonized
Standards,
and state of the art,
to demonstrate that products, services
or processes comply with Essential principles
of safety and performance.
EN 60601-1
EN 62304
EN 14971
EN 82304
EN 62366
ISO 80001-1
ISO 80001-2-1
ISO 80001-2-2
ISO 80001-2-4
AAMI TIR57/Ed. 1,
Principles for medical
device security—Risk
management
GAMP5, CANADA 2019
cybersecurity guidance,
Australian TGA medical
device cybersecurity
guidance, NIST, AAMI, UL
29000 , ISO 2700X ...
risk management
AAMI TIR57/Ed. 1
17.2. For devices that incorporate software or for software
that are devices in themselves, the
software shall be developed and manufactured in
accordance with the state of the art
including information security,verification and validation.
taking into account the principles of development life cycle,
3antonio.bartolozzi@bartolozzi.it
AAMI TIR 57
Bi-dimensional
Risk Analysis
4antonio.bartolozzi@bartolozzi.it
AAMI TIR 57
Because threatschange over timeand new vulnerabilities in operating systems
middleware and components are discovered
on regular basis security risks are frequently identified
after a device is released to the market
Example : operating system vulnerability
5antonio.bartolozzi@bartolozzi.it
Operating System
Operating system vulnerability
Spo2
96
%
NIBP 250/105
mmHg
HR 120
bpm
High blood Pressure John Doe
Vulnerability
Attack
USE AAMI TIR57
6antonio.bartolozzi@bartolozzi.it
AAMI TIR57 Security  Safety
Risk : OS Vulnerability
Security Risk
Control
constantly update operating system
Safety Risk : Medical device in uncontrolled environment
Not acceptable safety risk
Safety risk analysis
Security risk analysis
7antonio.bartolozzi@bartolozzi.it
AAMI TIR57 Risk Analysis – Safety  Security
OS Vulnerability
Safety Risk Control
Release updated OS only after complete test
Security Risk : Medical Device exposed to an attack for a long time
Not acceptable Security risk
Security Risk analysis
8antonio.bartolozzi@bartolozzi.it
There is NO Acceptable Risk control"
There is NO Acceptable Risk control
Change Design
9antonio.bartolozzi@bartolozzi.it
Change design
New Opering
system barriers
Use LEGO-like
Operating system
• Strong firewall whitelist based
• Advanced Operating System Process
Manager
Minimize
Operating
system
10antonio.bartolozzi@bartolozzi.it
Example - Windows Embedded
Customized
Operating system
Low memory usage  10 MB!
Not standard port and service !
(old)
Less ComponentsLess Memory
more stability
less cyber-attacks
11
firewall whitelisting
OS
ATTACK OS Driver
OS Filter
Guardian
Kill
NAK
White list
Software Antivirus
API Access
There is no need of os upgrade
Manufacturer knows al right
processes and right
operations of the system

More Related Content

What's hot

The Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMDThe Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMD
Janel Heilbrunn
 
Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM
Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALMApplying IEC 62304 Risk Management in Aligned Elements - the medical device ALM
Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM
Aligned AG
 
FDA UDI vs EU UDI
FDA UDI vs EU UDIFDA UDI vs EU UDI
FDA UDI vs EU UDI
mitchellrobertss
 
Medical Device Regulation (MDR) overview for Technion, May 25, 2021
Medical Device Regulation (MDR) overview for Technion, May 25, 2021Medical Device Regulation (MDR) overview for Technion, May 25, 2021
Medical Device Regulation (MDR) overview for Technion, May 25, 2021
Levi Shapiro
 
mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...
mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...
mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...
Levi Shapiro
 
Medical Devices Regulation (MDR) 2017/745 - Annex XI, Conformity assessment,...
Medical Devices Regulation (MDR)  2017/745 - Annex XI, Conformity assessment,...Medical Devices Regulation (MDR)  2017/745 - Annex XI, Conformity assessment,...
Medical Devices Regulation (MDR) 2017/745 - Annex XI, Conformity assessment,...
Arete-Zoe, LLC
 
Medical Devices Regulation (MDR) 2017/745 - Classification of devices
Medical Devices Regulation (MDR)  2017/745 - Classification of devices Medical Devices Regulation (MDR)  2017/745 - Classification of devices
Medical Devices Regulation (MDR) 2017/745 - Classification of devices
Arete-Zoe, LLC
 
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
Greenlight Guru
 
8.RiskManagement.ppt
8.RiskManagement.ppt8.RiskManagement.ppt
8.RiskManagement.ppt
ssuser242c61
 
European MDR - Understanding Safety and Performance Requirements
European MDR - Understanding Safety and Performance RequirementsEuropean MDR - Understanding Safety and Performance Requirements
European MDR - Understanding Safety and Performance Requirements
Kirsten Bertelsen
 
EU MDR
EU MDR EU MDR
EU MDR
RohitParkale
 
Rule 11 vs Rule 10 UE 2017-745 v01
Rule 11  vs Rule 10 UE 2017-745 v01Rule 11  vs Rule 10 UE 2017-745 v01
Rule 11 vs Rule 10 UE 2017-745 v01
Antonio Bartolozzi
 
Regulation of software as medical devices
Regulation of software as medical devicesRegulation of software as medical devices
Regulation of software as medical devices
TGA Australia
 
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
Greenlight Guru
 
Update on software as a medical device (SaMD)
Update on software as a medical device (SaMD)Update on software as a medical device (SaMD)
Update on software as a medical device (SaMD)
TGA Australia
 
Canadaapprovalprocess final13june2012-130116090730-phpapp01
Canadaapprovalprocess final13june2012-130116090730-phpapp01Canadaapprovalprocess final13june2012-130116090730-phpapp01
Canadaapprovalprocess final13june2012-130116090730-phpapp01
Frank Ferguson
 
Advamed MDR IVDR update
Advamed MDR IVDR updateAdvamed MDR IVDR update
Advamed MDR IVDR update
Erik Vollebregt
 
IEC 62304 Action List
IEC 62304 Action List IEC 62304 Action List
IEC 62304 Action List
MethodSense, Inc.
 
Medical Devices Regulation (MDR) 2017/745 - Clinical Evaluation & Post-Marke...
Medical Devices Regulation (MDR)  2017/745 - Clinical Evaluation & Post-Marke...Medical Devices Regulation (MDR)  2017/745 - Clinical Evaluation & Post-Marke...
Medical Devices Regulation (MDR) 2017/745 - Clinical Evaluation & Post-Marke...
Arete-Zoe, LLC
 
EU Medical Device Regulatory Framework_Dec, 2022
EU Medical Device Regulatory Framework_Dec, 2022EU Medical Device Regulatory Framework_Dec, 2022
EU Medical Device Regulatory Framework_Dec, 2022
Levi Shapiro
 

What's hot (20)

The Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMDThe Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMD
 
Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM
Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALMApplying IEC 62304 Risk Management in Aligned Elements - the medical device ALM
Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM
 
FDA UDI vs EU UDI
FDA UDI vs EU UDIFDA UDI vs EU UDI
FDA UDI vs EU UDI
 
Medical Device Regulation (MDR) overview for Technion, May 25, 2021
Medical Device Regulation (MDR) overview for Technion, May 25, 2021Medical Device Regulation (MDR) overview for Technion, May 25, 2021
Medical Device Regulation (MDR) overview for Technion, May 25, 2021
 
mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...
mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...
mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...
 
Medical Devices Regulation (MDR) 2017/745 - Annex XI, Conformity assessment,...
Medical Devices Regulation (MDR)  2017/745 - Annex XI, Conformity assessment,...Medical Devices Regulation (MDR)  2017/745 - Annex XI, Conformity assessment,...
Medical Devices Regulation (MDR) 2017/745 - Annex XI, Conformity assessment,...
 
Medical Devices Regulation (MDR) 2017/745 - Classification of devices
Medical Devices Regulation (MDR)  2017/745 - Classification of devices Medical Devices Regulation (MDR)  2017/745 - Classification of devices
Medical Devices Regulation (MDR) 2017/745 - Classification of devices
 
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
 
8.RiskManagement.ppt
8.RiskManagement.ppt8.RiskManagement.ppt
8.RiskManagement.ppt
 
European MDR - Understanding Safety and Performance Requirements
European MDR - Understanding Safety and Performance RequirementsEuropean MDR - Understanding Safety and Performance Requirements
European MDR - Understanding Safety and Performance Requirements
 
EU MDR
EU MDR EU MDR
EU MDR
 
Rule 11 vs Rule 10 UE 2017-745 v01
Rule 11  vs Rule 10 UE 2017-745 v01Rule 11  vs Rule 10 UE 2017-745 v01
Rule 11 vs Rule 10 UE 2017-745 v01
 
Regulation of software as medical devices
Regulation of software as medical devicesRegulation of software as medical devices
Regulation of software as medical devices
 
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
Implementing a Global Unique Device Identification (UDI) Solution: Regional U...
 
Update on software as a medical device (SaMD)
Update on software as a medical device (SaMD)Update on software as a medical device (SaMD)
Update on software as a medical device (SaMD)
 
Canadaapprovalprocess final13june2012-130116090730-phpapp01
Canadaapprovalprocess final13june2012-130116090730-phpapp01Canadaapprovalprocess final13june2012-130116090730-phpapp01
Canadaapprovalprocess final13june2012-130116090730-phpapp01
 
Advamed MDR IVDR update
Advamed MDR IVDR updateAdvamed MDR IVDR update
Advamed MDR IVDR update
 
IEC 62304 Action List
IEC 62304 Action List IEC 62304 Action List
IEC 62304 Action List
 
Medical Devices Regulation (MDR) 2017/745 - Clinical Evaluation & Post-Marke...
Medical Devices Regulation (MDR)  2017/745 - Clinical Evaluation & Post-Marke...Medical Devices Regulation (MDR)  2017/745 - Clinical Evaluation & Post-Marke...
Medical Devices Regulation (MDR) 2017/745 - Clinical Evaluation & Post-Marke...
 
EU Medical Device Regulatory Framework_Dec, 2022
EU Medical Device Regulatory Framework_Dec, 2022EU Medical Device Regulatory Framework_Dec, 2022
EU Medical Device Regulatory Framework_Dec, 2022
 

Similar to Bi-dimensional risk analysis - safety&security -software medical device

How to Achieve Functional Safety in Safety-Citical Embedded Systems
How to Achieve Functional Safety in Safety-Citical Embedded SystemsHow to Achieve Functional Safety in Safety-Citical Embedded Systems
How to Achieve Functional Safety in Safety-Citical Embedded Systems
evatjohnson
 
How to Achieve Functional Safety in Safety-Critical Embedded Systems
How to Achieve Functional Safety in Safety-Critical Embedded SystemsHow to Achieve Functional Safety in Safety-Critical Embedded Systems
How to Achieve Functional Safety in Safety-Critical Embedded Systems
Intland Software GmbH
 
safety-instrumented-systems for cbemical
safety-instrumented-systems for cbemicalsafety-instrumented-systems for cbemical
safety-instrumented-systems for cbemical
Josh Jay
 
safety-instrumented-systems-summers.ppt
safety-instrumented-systems-summers.pptsafety-instrumented-systems-summers.ppt
safety-instrumented-systems-summers.ppt
editorschoice1
 
Safety instrumented systems angela summers
Safety instrumented systems angela summers Safety instrumented systems angela summers
Safety instrumented systems angela summers
Ahmed Gamal
 
Smart Manufacturing
Smart ManufacturingSmart Manufacturing
Smart Manufacturing
CSA Group
 
Introduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL CertificationIntroduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL Certification
ISA Boston Section
 
Safety of machinery - Application of standard EN ISO 13849-1
Safety of machinery - Application of standard EN ISO 13849-1Safety of machinery - Application of standard EN ISO 13849-1
Safety of machinery - Application of standard EN ISO 13849-1
dnunez1984
 
Safety of machinery
Safety of machinerySafety of machinery
Safety of machinery
Vo Quoc Hieu
 
InTech-FOCUS-Process-Safety-Sept2020.pdf
InTech-FOCUS-Process-Safety-Sept2020.pdfInTech-FOCUS-Process-Safety-Sept2020.pdf
InTech-FOCUS-Process-Safety-Sept2020.pdf
glan Glandeva
 
Medical Risk Management
Medical Risk ManagementMedical Risk Management
Medical Risk Management
Intland Software GmbH
 
ISO/IEC80001 - Do we need another standard?
ISO/IEC80001 - Do we need another standard?ISO/IEC80001 - Do we need another standard?
ISO/IEC80001 - Do we need another standard?
Robert Ginsberg
 
Application of Combustion Analyzers in Safety Instrumented Systems
Application of Combustion Analyzers in Safety Instrumented SystemsApplication of Combustion Analyzers in Safety Instrumented Systems
Application of Combustion Analyzers in Safety Instrumented Systems
Belilove Company-Engineers
 
Sicurezza Industrie4.0 - E M Tieghi templ Assintel_short
Sicurezza Industrie4.0 - E M Tieghi templ Assintel_shortSicurezza Industrie4.0 - E M Tieghi templ Assintel_short
Sicurezza Industrie4.0 - E M Tieghi templ Assintel_short
Enzo M. Tieghi
 
MDR- Significant changes in the design and intended purpose
MDR- Significant changes in the design and intended purposeMDR- Significant changes in the design and intended purpose
MDR- Significant changes in the design and intended purpose
Antonio Bartolozzi
 
Alarm process basics for dummies
Alarm process basics for dummiesAlarm process basics for dummies
Alarm process basics for dummies
rajendrachougale1975
 
BlackHat_2015_Slides_Krotofil_FINAL
BlackHat_2015_Slides_Krotofil_FINALBlackHat_2015_Slides_Krotofil_FINAL
BlackHat_2015_Slides_Krotofil_FINAL
Marina Krotofil
 
wincc_flexible_2008_sp4_smart_panels_enus.pdf
wincc_flexible_2008_sp4_smart_panels_enus.pdfwincc_flexible_2008_sp4_smart_panels_enus.pdf
wincc_flexible_2008_sp4_smart_panels_enus.pdf
MarioHaguila
 
Resilient systems design
Resilient systems designResilient systems design
Resilient systems design
Edward Jones
 
Resilient systems design
Resilient systems designResilient systems design
Resilient systems design
Edward Jones
 

Similar to Bi-dimensional risk analysis - safety&security -software medical device (20)

How to Achieve Functional Safety in Safety-Citical Embedded Systems
How to Achieve Functional Safety in Safety-Citical Embedded SystemsHow to Achieve Functional Safety in Safety-Citical Embedded Systems
How to Achieve Functional Safety in Safety-Citical Embedded Systems
 
How to Achieve Functional Safety in Safety-Critical Embedded Systems
How to Achieve Functional Safety in Safety-Critical Embedded SystemsHow to Achieve Functional Safety in Safety-Critical Embedded Systems
How to Achieve Functional Safety in Safety-Critical Embedded Systems
 
safety-instrumented-systems for cbemical
safety-instrumented-systems for cbemicalsafety-instrumented-systems for cbemical
safety-instrumented-systems for cbemical
 
safety-instrumented-systems-summers.ppt
safety-instrumented-systems-summers.pptsafety-instrumented-systems-summers.ppt
safety-instrumented-systems-summers.ppt
 
Safety instrumented systems angela summers
Safety instrumented systems angela summers Safety instrumented systems angela summers
Safety instrumented systems angela summers
 
Smart Manufacturing
Smart ManufacturingSmart Manufacturing
Smart Manufacturing
 
Introduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL CertificationIntroduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL Certification
 
Safety of machinery - Application of standard EN ISO 13849-1
Safety of machinery - Application of standard EN ISO 13849-1Safety of machinery - Application of standard EN ISO 13849-1
Safety of machinery - Application of standard EN ISO 13849-1
 
Safety of machinery
Safety of machinerySafety of machinery
Safety of machinery
 
InTech-FOCUS-Process-Safety-Sept2020.pdf
InTech-FOCUS-Process-Safety-Sept2020.pdfInTech-FOCUS-Process-Safety-Sept2020.pdf
InTech-FOCUS-Process-Safety-Sept2020.pdf
 
Medical Risk Management
Medical Risk ManagementMedical Risk Management
Medical Risk Management
 
ISO/IEC80001 - Do we need another standard?
ISO/IEC80001 - Do we need another standard?ISO/IEC80001 - Do we need another standard?
ISO/IEC80001 - Do we need another standard?
 
Application of Combustion Analyzers in Safety Instrumented Systems
Application of Combustion Analyzers in Safety Instrumented SystemsApplication of Combustion Analyzers in Safety Instrumented Systems
Application of Combustion Analyzers in Safety Instrumented Systems
 
Sicurezza Industrie4.0 - E M Tieghi templ Assintel_short
Sicurezza Industrie4.0 - E M Tieghi templ Assintel_shortSicurezza Industrie4.0 - E M Tieghi templ Assintel_short
Sicurezza Industrie4.0 - E M Tieghi templ Assintel_short
 
MDR- Significant changes in the design and intended purpose
MDR- Significant changes in the design and intended purposeMDR- Significant changes in the design and intended purpose
MDR- Significant changes in the design and intended purpose
 
Alarm process basics for dummies
Alarm process basics for dummiesAlarm process basics for dummies
Alarm process basics for dummies
 
BlackHat_2015_Slides_Krotofil_FINAL
BlackHat_2015_Slides_Krotofil_FINALBlackHat_2015_Slides_Krotofil_FINAL
BlackHat_2015_Slides_Krotofil_FINAL
 
wincc_flexible_2008_sp4_smart_panels_enus.pdf
wincc_flexible_2008_sp4_smart_panels_enus.pdfwincc_flexible_2008_sp4_smart_panels_enus.pdf
wincc_flexible_2008_sp4_smart_panels_enus.pdf
 
Resilient systems design
Resilient systems designResilient systems design
Resilient systems design
 
Resilient systems design
Resilient systems designResilient systems design
Resilient systems design
 

More from Antonio Bartolozzi

MDCG 2020 Guidance on significant changes- Review, problems and tips
MDCG 2020 Guidance on significant changes- Review, problems and tipsMDCG 2020 Guidance on significant changes- Review, problems and tips
MDCG 2020 Guidance on significant changes- Review, problems and tips
Antonio Bartolozzi
 
Automatically Convert Oracle Forms Code to Delphi Code
Automatically Convert Oracle Forms Code to Delphi CodeAutomatically Convert Oracle Forms Code to Delphi Code
Automatically Convert Oracle Forms Code to Delphi Code
Antonio Bartolozzi
 
Lesson 2 - convert a real application (Oracle Form => Delphi)
Lesson 2 - convert a real application (Oracle Form => Delphi)Lesson 2 - convert a real application (Oracle Form => Delphi)
Lesson 2 - convert a real application (Oracle Form => Delphi)
Antonio Bartolozzi
 
Lesson1-How to migrate your Forms code and build HTM5 APP
Lesson1-How to migrate your Forms code and build HTM5 APPLesson1-How to migrate your Forms code and build HTM5 APP
Lesson1-How to migrate your Forms code and build HTM5 APP
Antonio Bartolozzi
 
Windows xp/7 - What can we do ?
Windows xp/7 - What can we do ?Windows xp/7 - What can we do ?
Windows xp/7 - What can we do ?
Antonio Bartolozzi
 
Clinical investigations - Intended Normal condition of use
Clinical investigations - Intended Normal condition of use Clinical investigations - Intended Normal condition of use
Clinical investigations - Intended Normal condition of use
Antonio Bartolozzi
 
Review Mdcg 2019-11 guidance on qualification and classification of software
Review Mdcg 2019-11 guidance on qualification and classification of software Review Mdcg 2019-11 guidance on qualification and classification of software
Review Mdcg 2019-11 guidance on qualification and classification of software
Antonio Bartolozzi
 
Mdcg 2019 11 guidance on qualification and classification of software mdr-ivdr
Mdcg 2019 11 guidance on qualification and classification of software mdr-ivdrMdcg 2019 11 guidance on qualification and classification of software mdr-ivdr
Mdcg 2019 11 guidance on qualification and classification of software mdr-ivdr
Antonio Bartolozzi
 
Rule 11 and imdrf ue 2017 745 v06
Rule 11 and imdrf ue 2017 745 v06Rule 11 and imdrf ue 2017 745 v06
Rule 11 and imdrf ue 2017 745 v06
Antonio Bartolozzi
 
EU 2017/745 Rule 11 (re)interpretation
EU 2017/745 Rule 11 (re)interpretation EU 2017/745 Rule 11 (re)interpretation
EU 2017/745 Rule 11 (re)interpretation
Antonio Bartolozzi
 

More from Antonio Bartolozzi (10)

MDCG 2020 Guidance on significant changes- Review, problems and tips
MDCG 2020 Guidance on significant changes- Review, problems and tipsMDCG 2020 Guidance on significant changes- Review, problems and tips
MDCG 2020 Guidance on significant changes- Review, problems and tips
 
Automatically Convert Oracle Forms Code to Delphi Code
Automatically Convert Oracle Forms Code to Delphi CodeAutomatically Convert Oracle Forms Code to Delphi Code
Automatically Convert Oracle Forms Code to Delphi Code
 
Lesson 2 - convert a real application (Oracle Form => Delphi)
Lesson 2 - convert a real application (Oracle Form => Delphi)Lesson 2 - convert a real application (Oracle Form => Delphi)
Lesson 2 - convert a real application (Oracle Form => Delphi)
 
Lesson1-How to migrate your Forms code and build HTM5 APP
Lesson1-How to migrate your Forms code and build HTM5 APPLesson1-How to migrate your Forms code and build HTM5 APP
Lesson1-How to migrate your Forms code and build HTM5 APP
 
Windows xp/7 - What can we do ?
Windows xp/7 - What can we do ?Windows xp/7 - What can we do ?
Windows xp/7 - What can we do ?
 
Clinical investigations - Intended Normal condition of use
Clinical investigations - Intended Normal condition of use Clinical investigations - Intended Normal condition of use
Clinical investigations - Intended Normal condition of use
 
Review Mdcg 2019-11 guidance on qualification and classification of software
Review Mdcg 2019-11 guidance on qualification and classification of software Review Mdcg 2019-11 guidance on qualification and classification of software
Review Mdcg 2019-11 guidance on qualification and classification of software
 
Mdcg 2019 11 guidance on qualification and classification of software mdr-ivdr
Mdcg 2019 11 guidance on qualification and classification of software mdr-ivdrMdcg 2019 11 guidance on qualification and classification of software mdr-ivdr
Mdcg 2019 11 guidance on qualification and classification of software mdr-ivdr
 
Rule 11 and imdrf ue 2017 745 v06
Rule 11 and imdrf ue 2017 745 v06Rule 11 and imdrf ue 2017 745 v06
Rule 11 and imdrf ue 2017 745 v06
 
EU 2017/745 Rule 11 (re)interpretation
EU 2017/745 Rule 11 (re)interpretation EU 2017/745 Rule 11 (re)interpretation
EU 2017/745 Rule 11 (re)interpretation
 

Recently uploaded

PET CT beginners Guide covers some of the underrepresented topics in PET CT
PET CT  beginners Guide  covers some of the underrepresented topics  in PET CTPET CT  beginners Guide  covers some of the underrepresented topics  in PET CT
PET CT beginners Guide covers some of the underrepresented topics in PET CT
MiadAlsulami
 
Unlocking the Secrets to Safe Patient Handling.pdf
Unlocking the Secrets to Safe Patient Handling.pdfUnlocking the Secrets to Safe Patient Handling.pdf
Unlocking the Secrets to Safe Patient Handling.pdf
Lift Ability
 
Hypertension and it's role of physiotherapy in it.
Hypertension and it's role of physiotherapy in it.Hypertension and it's role of physiotherapy in it.
Hypertension and it's role of physiotherapy in it.
Vishal kr Thakur
 
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
DR Jag Mohan Prajapati
 
Can coffee help me lose weight? Yes, 25,422 users in the USA use it for that ...
Can coffee help me lose weight? Yes, 25,422 users in the USA use it for that ...Can coffee help me lose weight? Yes, 25,422 users in the USA use it for that ...
Can coffee help me lose weight? Yes, 25,422 users in the USA use it for that ...
nirahealhty
 
Rate Controlled Drug Delivery Systems.pdf
Rate Controlled Drug Delivery Systems.pdfRate Controlled Drug Delivery Systems.pdf
Rate Controlled Drug Delivery Systems.pdf
Rajarambapu College of Pharmacy Kasegaon Dist Sangli
 
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
The Lifesciences Magazine
 
KEY Points of Leicester travel clinic In London doc.docx
KEY Points of Leicester travel clinic In London doc.docxKEY Points of Leicester travel clinic In London doc.docx
KEY Points of Leicester travel clinic In London doc.docx
NX Healthcare
 
NEEDLE STICK INJURY - JOURNAL CLUB PRESENTATION - DR SHAMIN EABENSON
NEEDLE STICK INJURY - JOURNAL CLUB PRESENTATION - DR SHAMIN EABENSONNEEDLE STICK INJURY - JOURNAL CLUB PRESENTATION - DR SHAMIN EABENSON
NEEDLE STICK INJURY - JOURNAL CLUB PRESENTATION - DR SHAMIN EABENSON
SHAMIN EABENSON
 
Top massage center in ajman chandrima Spa
Top massage center in ajman chandrima  SpaTop massage center in ajman chandrima  Spa
Top massage center in ajman chandrima Spa
Chandrima Spa Ajman
 
LGBTQ+ Adults: Unique Opportunities and Inclusive Approaches to Care
LGBTQ+ Adults: Unique Opportunities and Inclusive Approaches to CareLGBTQ+ Adults: Unique Opportunities and Inclusive Approaches to Care
LGBTQ+ Adults: Unique Opportunities and Inclusive Approaches to Care
VITASAuthor
 
The Power of Superfoods and Exercise.pdf
The Power of Superfoods and Exercise.pdfThe Power of Superfoods and Exercise.pdf
The Power of Superfoods and Exercise.pdf
Dr Rachana Gujar
 
Pediatric Emergency Care for Children | Apollo Hospital
Pediatric Emergency Care for Children | Apollo HospitalPediatric Emergency Care for Children | Apollo Hospital
Pediatric Emergency Care for Children | Apollo Hospital
Apollo 24/7 Adult & Paediatric Emergency Services
 
Gemma Wean- Nutritional solution for Artemia
Gemma Wean- Nutritional solution for ArtemiaGemma Wean- Nutritional solution for Artemia
Gemma Wean- Nutritional solution for Artemia
smuskaan0008
 
Time line.ppQAWSDRFTGYUIOPÑLKIUYTREWASDFTGY
Time line.ppQAWSDRFTGYUIOPÑLKIUYTREWASDFTGYTime line.ppQAWSDRFTGYUIOPÑLKIUYTREWASDFTGY
Time line.ppQAWSDRFTGYUIOPÑLKIUYTREWASDFTGY
DianaRodriguez639773
 
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
blessyjannu21
 
Empowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
Empowering ACOs: Leveraging Quality Management Tools for MIPS and BeyondEmpowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
Empowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
Health Catalyst
 
DRAFT Ventilator Rapid Reference version 2.4.pdf
DRAFT Ventilator Rapid Reference  version  2.4.pdfDRAFT Ventilator Rapid Reference  version  2.4.pdf
DRAFT Ventilator Rapid Reference version 2.4.pdf
Robert Cole
 
Let's Talk About It: Breast Cancer (What is Mindset and Does it Really Matter?)
Let's Talk About It: Breast Cancer (What is Mindset and Does it Really Matter?)Let's Talk About It: Breast Cancer (What is Mindset and Does it Really Matter?)
Let's Talk About It: Breast Cancer (What is Mindset and Does it Really Matter?)
bkling
 
MBC Support Group for Black Women – Insights in Genetic Testing.pdf
MBC Support Group for Black Women – Insights in Genetic Testing.pdfMBC Support Group for Black Women – Insights in Genetic Testing.pdf
MBC Support Group for Black Women – Insights in Genetic Testing.pdf
bkling
 

Recently uploaded (20)

PET CT beginners Guide covers some of the underrepresented topics in PET CT
PET CT  beginners Guide  covers some of the underrepresented topics  in PET CTPET CT  beginners Guide  covers some of the underrepresented topics  in PET CT
PET CT beginners Guide covers some of the underrepresented topics in PET CT
 
Unlocking the Secrets to Safe Patient Handling.pdf
Unlocking the Secrets to Safe Patient Handling.pdfUnlocking the Secrets to Safe Patient Handling.pdf
Unlocking the Secrets to Safe Patient Handling.pdf
 
Hypertension and it's role of physiotherapy in it.
Hypertension and it's role of physiotherapy in it.Hypertension and it's role of physiotherapy in it.
Hypertension and it's role of physiotherapy in it.
 
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
DELIRIUM BY DR JAGMOHAN PRAJAPATI.......
 
Can coffee help me lose weight? Yes, 25,422 users in the USA use it for that ...
Can coffee help me lose weight? Yes, 25,422 users in the USA use it for that ...Can coffee help me lose weight? Yes, 25,422 users in the USA use it for that ...
Can coffee help me lose weight? Yes, 25,422 users in the USA use it for that ...
 
Rate Controlled Drug Delivery Systems.pdf
Rate Controlled Drug Delivery Systems.pdfRate Controlled Drug Delivery Systems.pdf
Rate Controlled Drug Delivery Systems.pdf
 
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
 
KEY Points of Leicester travel clinic In London doc.docx
KEY Points of Leicester travel clinic In London doc.docxKEY Points of Leicester travel clinic In London doc.docx
KEY Points of Leicester travel clinic In London doc.docx
 
NEEDLE STICK INJURY - JOURNAL CLUB PRESENTATION - DR SHAMIN EABENSON
NEEDLE STICK INJURY - JOURNAL CLUB PRESENTATION - DR SHAMIN EABENSONNEEDLE STICK INJURY - JOURNAL CLUB PRESENTATION - DR SHAMIN EABENSON
NEEDLE STICK INJURY - JOURNAL CLUB PRESENTATION - DR SHAMIN EABENSON
 
Top massage center in ajman chandrima Spa
Top massage center in ajman chandrima  SpaTop massage center in ajman chandrima  Spa
Top massage center in ajman chandrima Spa
 
LGBTQ+ Adults: Unique Opportunities and Inclusive Approaches to Care
LGBTQ+ Adults: Unique Opportunities and Inclusive Approaches to CareLGBTQ+ Adults: Unique Opportunities and Inclusive Approaches to Care
LGBTQ+ Adults: Unique Opportunities and Inclusive Approaches to Care
 
The Power of Superfoods and Exercise.pdf
The Power of Superfoods and Exercise.pdfThe Power of Superfoods and Exercise.pdf
The Power of Superfoods and Exercise.pdf
 
Pediatric Emergency Care for Children | Apollo Hospital
Pediatric Emergency Care for Children | Apollo HospitalPediatric Emergency Care for Children | Apollo Hospital
Pediatric Emergency Care for Children | Apollo Hospital
 
Gemma Wean- Nutritional solution for Artemia
Gemma Wean- Nutritional solution for ArtemiaGemma Wean- Nutritional solution for Artemia
Gemma Wean- Nutritional solution for Artemia
 
Time line.ppQAWSDRFTGYUIOPÑLKIUYTREWASDFTGY
Time line.ppQAWSDRFTGYUIOPÑLKIUYTREWASDFTGYTime line.ppQAWSDRFTGYUIOPÑLKIUYTREWASDFTGY
Time line.ppQAWSDRFTGYUIOPÑLKIUYTREWASDFTGY
 
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
INFECTION OF THE BRAIN -ENCEPHALITIS ( PPT)
 
Empowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
Empowering ACOs: Leveraging Quality Management Tools for MIPS and BeyondEmpowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
Empowering ACOs: Leveraging Quality Management Tools for MIPS and Beyond
 
DRAFT Ventilator Rapid Reference version 2.4.pdf
DRAFT Ventilator Rapid Reference  version  2.4.pdfDRAFT Ventilator Rapid Reference  version  2.4.pdf
DRAFT Ventilator Rapid Reference version 2.4.pdf
 
Let's Talk About It: Breast Cancer (What is Mindset and Does it Really Matter?)
Let's Talk About It: Breast Cancer (What is Mindset and Does it Really Matter?)Let's Talk About It: Breast Cancer (What is Mindset and Does it Really Matter?)
Let's Talk About It: Breast Cancer (What is Mindset and Does it Really Matter?)
 
MBC Support Group for Black Women – Insights in Genetic Testing.pdf
MBC Support Group for Black Women – Insights in Genetic Testing.pdfMBC Support Group for Black Women – Insights in Genetic Testing.pdf
MBC Support Group for Black Women – Insights in Genetic Testing.pdf
 

Bi-dimensional risk analysis - safety&security -software medical device

  • 1. 1 AAMI TIR 57 Bi-dimensional Risk Analysis Security and safety design Antonio Bartolozzi antonio.bartolozzi@bartolozzi.it 25/11/2019
  • 2. 2antonio.bartolozzi@bartolozzi.it Electronic programmable systems – Essential principles of safety and performance state of the art use harmonized Standards, and state of the art, to demonstrate that products, services or processes comply with Essential principles of safety and performance. EN 60601-1 EN 62304 EN 14971 EN 82304 EN 62366 ISO 80001-1 ISO 80001-2-1 ISO 80001-2-2 ISO 80001-2-4 AAMI TIR57/Ed. 1, Principles for medical device security—Risk management GAMP5, CANADA 2019 cybersecurity guidance, Australian TGA medical device cybersecurity guidance, NIST, AAMI, UL 29000 , ISO 2700X ... risk management AAMI TIR57/Ed. 1 17.2. For devices that incorporate software or for software that are devices in themselves, the software shall be developed and manufactured in accordance with the state of the art including information security,verification and validation. taking into account the principles of development life cycle,
  • 4. 4antonio.bartolozzi@bartolozzi.it AAMI TIR 57 Because threatschange over timeand new vulnerabilities in operating systems middleware and components are discovered on regular basis security risks are frequently identified after a device is released to the market Example : operating system vulnerability
  • 5. 5antonio.bartolozzi@bartolozzi.it Operating System Operating system vulnerability Spo2 96 % NIBP 250/105 mmHg HR 120 bpm High blood Pressure John Doe Vulnerability Attack USE AAMI TIR57
  • 6. 6antonio.bartolozzi@bartolozzi.it AAMI TIR57 Security  Safety Risk : OS Vulnerability Security Risk Control constantly update operating system Safety Risk : Medical device in uncontrolled environment Not acceptable safety risk Safety risk analysis Security risk analysis
  • 7. 7antonio.bartolozzi@bartolozzi.it AAMI TIR57 Risk Analysis – Safety  Security OS Vulnerability Safety Risk Control Release updated OS only after complete test Security Risk : Medical Device exposed to an attack for a long time Not acceptable Security risk Security Risk analysis
  • 8. 8antonio.bartolozzi@bartolozzi.it There is NO Acceptable Risk control" There is NO Acceptable Risk control Change Design
  • 9. 9antonio.bartolozzi@bartolozzi.it Change design New Opering system barriers Use LEGO-like Operating system • Strong firewall whitelist based • Advanced Operating System Process Manager Minimize Operating system
  • 10. 10antonio.bartolozzi@bartolozzi.it Example - Windows Embedded Customized Operating system Low memory usage  10 MB! Not standard port and service ! (old) Less ComponentsLess Memory more stability less cyber-attacks
  • 11. 11 firewall whitelisting OS ATTACK OS Driver OS Filter Guardian Kill NAK White list Software Antivirus API Access There is no need of os upgrade Manufacturer knows al right processes and right operations of the system