IEEE 11073-40101-2020 - IEEE Approved Draft Standard - Health informatics - Device interoperability - Part 40101: Cybersecurity - Processes for vulnerability assessment
Standard Details
This standard defines for Personal Health Devices (PHDs) and Point-of-Care Devices (PoCDs) an iterative, systematic, scalable, and auditable approach to identification of cybersecurity vulnerabilities and estimation of risk. The standard presents one approach to iterative vulnerability assessment using the Spoofing, Tampering, Repudiation, Information Disclosure (STRIDE) classification scheme and embedded Common Vulnerability Scoring System (eCVSS) scoring system. The assessment includes system context, system decomposition, pre-mitigation scoring, mitigation, post-mitigation score and iterates until the remaining vulnerabilities are reduced to an acceptable level of risk.
Standards Committee
Status
Board Approval
Additional Resources Details
Working Group Details
Working Group
Working Group Chair
Standards Committee
Society
IEEE Program Manager
Active Projects
Existing Standards