Working Group Details
HDSecWG - Healthcare Device Security Assurance Working Group
|IEEE Program Manager|
P2621.2 - Standard for Wireless Diabetes Device Security Assurance: Protection Profile for Connected Diabetes Devices
This standard describes the security requirements, which compose a Protection Profile, for connected diabetes devices (CDDs). This standard includes: 1. Identification of relevant threats to CDDs and derivation of security objectives that counter those threats. 2. Derivation, from the security objectives, of security requirements for CDDs, taking into account the need to balance security and safe clinical application. 3. As part of that balance, differentiation between mandatory and optional requirements and specification of objectives that must be handled by the CDDs deployment environment rather than the CDD itself. 4. As part of that balance, definition of multiple levels of assurance requirements, enabling certification bodies and other stakeholders to apply a level of independent evaluation rigor that meets the collective and often varying needs across disparate situations, deployments, treatment criticality, and device type. 5. In order to be most useful for a broad audience of stakeholders, an informative layperson's explanation of CDD security requirements, in addition to the formal, normative requirements that follow the standardized requirements definition framework of ISO/IEC 15408.
This standard provides instruction for the safe use of consumer mobile devices (CMDs) in the control of diabetes-related medical devices, including: 1. The safe use of CMDs in both "open loop" and "closed loop" diabetes control solutions. 2. Instruction for the creation of security targets that leverage CMDs, with differentiated emphasis for security targets intended to meet the enhanced-basic and moderate assurance levels, as defined in other parts of this standard. 3. Instruction for leveraging CMDs in control solutions that have stringent real-time and high-availability (of the connected diabetes device (CDD) solution and/or its enclosing personal area network) requirements.