FDA Cybersecurity Regulations and Community Approach

bsides las vegas 2015 tuesday august 4 2015 n.w
1 / 11
Embed
Share

Explore the FDA's role in overseeing medical devices and the importance of cybersecurity in the healthcare industry. Learn about key takeaways and how security researchers are crucial in ensuring safe and effective devices.

  • FDA
  • Cybersecurity
  • Medical Devices
  • Healthcare
  • Regulations

Uploaded on | 0 Views


Download Presentation

Please find below an Image/Link to download the presentation.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author. If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.

You are allowed to download the files provided on this website for personal or commercial use, subject to the condition that they are used lawfully. All files are the property of their respective owners.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.

E N D

Presentation Transcript


  1. BSides Las Vegas 2015 Tuesday, August 4, 2015

  2. Medical Overview Many, many stakeholders Diversity of devices, from swallowable pills to enormous radiological devices. Something that affects nearly all of us. Many researchers are also patients of these treatments. So it s very visceral, and easy to demonstrate why it matters. One of the most critical single stakeholders is the FDA.

  3. Introducing the FDA Suzanne Schwartz Director Emergency Preparedness/Operations & Medical Countermeasures (EMCM)

  4. FDA Organization Department Of Health and Human Services Secretary Food and Drug Administration Office of the Commissioner Office of Global Regulatory Operations and Policy Office of Medical Products and Tobacco Office of the Chief Scientist Office of Foods Center for Devices and Radiological Health (CDRH) Center for Biologicals Evaluation and Research (CBER) Center for Drug Evaluation and Research (CDER) Center for Tobacco Products (CTP) Center for Veterinary Medicine (CVM) National Center for Toxicological Research (NCTR) Center for Food Safety and Applied Nutrition (CFSAN) Office of Regulatory Affairs (ORA) 4

  5. The products we regulate The products we regulate See the full picture in detail 5

  6. CDRH/FDA Goals Meet our mission: safe and effective devices Raise cyber-security awareness leverage knowledge from other industry sectors Promote safety and security by design by clear regulatory expectation Promote coordinated vulnerability disclosure & proactive vulnerability management Minimize reactive approaches Foster whole of community approach 6

  7. Key Takeaways FDA seeks to foster a whole of community approach That means security researchers play an important role! Establish a Cybersecurity Risk Management Program Make cyber hygiene paramount Create a trusted environment for information sharing Software updates for cybersecurity do not require pre-market review or recall (there are some exceptions) Slide 7

  8. Highlights from the past year Atlantic Council workshop and paper1 FDA Pre-Market Guidance and Workshop2 IEEE Workshop Embraced by healthcare community conferences Atlantic Council Cyber Wednesday3 Vulnerability Disclosure Policies Vulnerability Disclosure Brainstorming and Education with FDA Safety Communications BEFORE evidence of harm 1http://www.atlanticcouncil.org/publications/reports/the-healthcare-internet-of-things-rewards-and-risks 2http://www.fda.gov/MedicalDevices/NewsEvents/WorkshopsConferences/ucm412979.htm 3http://www.atlanticcouncil.org/events/webcasts/cyber-risk-wednesday-the-healthcare-internet-of-things-rewards-and-risks

  9. Highlights from the past year With FDA as a key partner Atlantic Council workshop and paper1 FDA Pre-Market Guidance and Workshop2 IEEE Workshop Embraced by healthcare community conferences Atlantic Council Cyber Wednesday3 Vulnerability Disclosure Policies Vulnerability Disclosure Brainstorming and Education with FDA Safety Communications BEFORE evidence of harm 1http://www.atlanticcouncil.org/publications/reports/the-healthcare-internet-of-things-rewards-and-risks 2http://www.fda.gov/MedicalDevices/NewsEvents/WorkshopsConferences/ucm412979.htm 3http://www.atlanticcouncil.org/events/webcasts/cyber-risk-wednesday-the-healthcare-internet-of-things-rewards-and-risks

  10. Coming Connected Medical Device Procurement Guide Hippocratic Oath for Connected Medical Devices D0 N0 H4rm

  11. Q&A

Related


More Related Content