Life Sciences & Health Care, Medical Device Manufacturing - Cybersecurity Strategy

The Life Science and Health Care (LSHC) – Market presents great opportunities. This article introduces foundational regulatory and cloud frameworks knowledge that would assist cybersecurity and regulatory professionals. Topics cover Frameworks, Standards & Tools, necessary for a CISO wishing to address MDM Cybersecurity, followed by insights regarding Mapping and Tagging, EnterpriseGRC Solutions Unification within GRC, and Cybersecurity Risk Management.

Here's the PDF download for the presentation and two options for viewing, as the slides only, or as the presentation delivered to ISC2 East Bay in August of 2019.

Just the slides (because silence is golden). If you want a discussion, it's on the next page.

Live discussion (2 hours, so proceed with caution!)

Life Sciences & Health Care Medical Device Manufacturing and Cybersecurity

(This presentation was created in the first year of the Pandemic. As we start year three, it's become more relevant.)

As the Pandemic moves to its sixth month, we see a shift not only in our prioritization of health issues but how we do medicine and the implications of cybersecurity across the proliferation of attack services ranging from devices to home computing.

  • Life Science and Health Care (LSHC) – Market, Players, Opportunities
  • Two key documents for learning – BSI Cybersecurity of Medical Devices; MDIC Medical Device Cybersecurity Report
  • Cyber Related Standards
  • Frameworks, Standards & Tools, How CISO’s Address MDM Cybersecurity
  • List of resources and Laws
  • IoT and CCPA
  • Mapping and Tagging – Unification within GRC and Cybersecurity Risk Management
  • Integration Progress – Facilitated Compliance Management
  • Investment in Licenses and Partners

(Your Presenter: Hey, this is me!)

Robin Basham is the owner EnterpriseGRC Solutions, President, ISC2 East Bay, Certified Information Systems Security (CISSP), Audit (CISA), Governance (CGEIT) and Risk (CRISC-N.A), ICT GRC expert and early adopter in both certifying and offering certification programs for Cloud Security and Virtualization, with industry experience in the management of systems, controls and data for SaaS (IaaS and PaaS), Finance, Healthcare, Banking, Education, Defense, and High Tech. Positions held include Technology Officer at State Street Bank, Leading Process Engineering for a major New England CLEC, Sr. Director Enterprise Technology for multiple advisory firms, founding, engineering product and running two governance software companies, and most recently Director Enterprise Compliance for a major player in the mortgage industry, Ellie Mae. Having served as Cisco, Unified Compliance, and ISMS Program Manager for a multi-year GRC project, Robin currently leads EnterpriseGRC Solutions LSHC initiative in support of three MDM clients. Robin may also be recognized for donating substantial time to supporting social platform security to further social democracy. Robin is also a past board member for the ISACA SV chapter.

Graphical representation that everyone asks for, so here they are:

Defense In Depth NHS view
Defense In-Depth, NHS View

Life Science & Health Care EnterpriseGRC Methodology

Products Necessary to GDPR


Standard, Law or Framework Web Link to Source
California Consumer Privacy Act of 2018 California Consumer Privacy Act (CCPA)
Eudralex Volume 4 Annex 11 – Computerized Systems Eudralex Volume 4 Annex 11 –Computerized Systems
GAMP® 5 Guide: A Risk-Based Approach to Compliant GxP Computerized Systems GAMP®5
HIPAA – HITECH Title 45 C.F.R. § 164 HIPAA – HITECH Title 45 C.F.R. § 164
ISO/IEC 27001:2013 € Information technology — Security techniques — Information security management systems — Requirements ISO/IEC 27001:2013 €
ISO 27799:2016 Health informatics — Information security management in health using ISO/IEC 27002 ISO 27799:2016
ISO/IEC 27002:2013 € Information technology — Security techniques — Code of practice for information security controls ISO/IEC 27002:2013 €
ISO/IEC 27017:2015 € 27002 for cloud services ISO/IEC 27017:2015 € 27002 for cloud services
ISO 13485:2016 – MEDICAL DEVICES – A PRACTICAL GUIDECAL DEVICES ISO 13485:2016 – MEDICAL DEVICES – A PRACTICAL GUIDECAL DEVICES
ISO/IEC 30111:2019 Information technology — Security techniques — Vulnerability handling processes ISO/IEC 30111:2019
ISO 14971:2019 Medical devices — Application of risk management to medical devices ISO 14971:2019 Medical devices — Application of risk management to medical devices “
HITRUST CSF v9.3 HITRUST ALLIANCE
Medical Device Cybersecurity Regional Incident Preparedness and Response Playbook (MITRE) Medical Device Cybersecurity Regional Incident Preparedness and Response Playbook
Premarket Management of Cybersecurity in Medical Devices Premarket Management of Cybersecurity in Medical Devices
Postmarket Management of Cybersecurity in Medical Devices Postmarket Management of Cybersecurity in Medical Devices
Title 21 CFR Part 11 CFR – Code of Federal Regulations Title 21 CHAPTER I–FOOD AND DRUG ADMINISTRATION PART 11 ELECTRONIC RECORDS; ELECTRONIC SIGNATURES
Title 21 CFR Part 820 QMS Requirements 21 CFR Part 820 QMS Requirements
*An overview of the medical device industry – MedPAC An overview of the medical device industry – MedPAC
*Cybersecurity of medical devices – Addressing patient safety and the security of patient health information Cybersecurity of medical devices

IoT and California Consumer Privacy Act, CCPA

TITLE 1.81.26. Security of Connected Devices, a new law, was designed to protect the security of IoT devices and the information those devices hold.

  • The law can be enforced only by the attorney general, a city attorney, a county counsel, or a district attorney, and does not provide for any right of private action.
  • The law does not apply to connected devices already subject to federal security standards.

The CCPA became effective on January 1, 2020

  • Officially called AB-375, CCPA is a bill that enhances privacy rights and consumer protection for residents of California. Signed into Law June 28, 2018, CCPA amends Part 4 of Division 3 of the California Civil Code.

Additional Exported content from the slides includes:

  • As Life Science & Health Care Industry is valued at $173 billion -> $208 billion in 2023 – The FDA Faces Increasing Cybersecurity Requirements
  • Heroes v. Innovators = Cyber-ready v. Closing Up Shop
  • Risk & Cybersecurity Requirements: Recent mandates in the Medical Device Market (MDM) – Under the US FDA

"… amongst healthcare stakeholders ... where addressing medical device risk has formerly focused on functional safety, and safety-related risk (to the exclusion of cybersecurity) or the protection of data, multiple approaches are now actively addressing the lifecycle risks and potential harm from cybersecurity incidents.

Medical devices manufacturers (MDM) are recommended to undertake a cybersecurity maturity assessment to identify and prioritize areas for improvement. This should include product lifecycle security, stipulated in emerging assessment schemes, which will be articulated in healthcare procurement. Mature incident response plans and processes are essential for all healthcare entities, in anticipation of the inevitable cybersecurity event."

  • Recent FDA mandates impact Medical Device Security and Extend beyond GxP Good Manufacturing to full Device Lifecycle

As medical devices and healthcare environments become interconnected … the risk of cybersecurity vulnerabilities impacting patient safety and privacy increases significantly. The Food and Drug Administration (FDA) now takes significant steps to develop policies and guidance to assist medical device manufacturers (MDMs) in addressing cybersecurity-related regulatory issues.

Stakeholders in the medical device industry closely examine how they can proactively address product security in an *ever-changing environment to quickly and effectively reduce any risks posed to patients. FDA guidance documents emphasize that medical device cybersecurity concerns must be addressed not only during the design and development of medical devices but also throughout the device lifecycle as potential cybersecurity vulnerabilities emerge.

  • Immediately Required Cyber Security Standards and Laws that Govern or Enable the Medical Device Market (MDM)
  • GAMP® 5 Guide: A Risk-Based Approach to Compliant GxP Computerized Systems*
  • Title 21 CFR Part 11 & Title 21 CFR Part 820 QMS Requirements
  • Title 45 CFR § 164 HIPAA - HITECH
  • Eudralex Volume 4 Annex 11 (Others may apply)
  • ISO/IEC 27001:2013 € and ISO/IEC 27002:2013 € or
  • ISO/IEC 27799:2016 € and ISO/IEC 27002:2013 €
  • ISO 13485:2016 - MEDICAL DEVICES - A PRACTICAL GUIDECAL DEVICES*
  • ISO 14971:2019 Medical devices — Application of risk management to medical devices*
  • HITRUST v9.3*
  • NIST Cybersecurity Framework v1.1

*Associated License Fee and Necessary for LSHC

  • Leaders Select, Implement and Prove Policy

Chief Risk, Chief Security, Chief Information Officers have a common objective:

IOT and California Consumer Privacy Act, CCPA

  • TITLE 1.81.26. Security of Connected Devices, a new law, was designed to protect the security of IoT devices and the information those devices hold.
  • The law can be enforced only by the attorney general, a city attorney, a county counsel, or a district attorney, and does not provide for any right of private action.
  • The law does not apply to connected devices already subject to federal security standards.
  • The CCPA effective on January 1, 2020
  • Officially called AB-375, CCPA is a bill that enhances privacy rights and consumer protection for residents of California. Signed into Law June 28, 2018, CCPA amends Part 4 of Division 3 of the California Civil Code.

Risk Models Vary by Business Role
– Differ on the What, Why & How

  • Models Seek to Organize Threats, Technologies, Treatments OR Model Risk Assessment Procedure, but usually not both
  • Regulation, Process, Threat, Assessments Don’t Tie Out
  • Cyber Security – NHS Perspective
  • Security Architecture Select Tools Used and Covered in Cyber Security Risk Assessment: Look for ways to automate the output of tools to the evidence of compliance
  • Look to Increase Common Threat Language as Tagging

We Leverage Mapping: HITRUST provides recommendations for mapping. Based upon a clients licensed engagement with HITRUST we leverage this mapping for them, however, we do not reproduce our mappings commercially.

  • ISO 13845:2016 used to Assess Title 21 CRF Part 820
  • Leverage Mapping: HITRUST, NIST800-53r5 – where we start
  • NIST 800-53 r5 Adds KEYWORDS and Privacy Attributes
  • Additional Resources that Tie Out IOT – CSA – Requires use of CSTAR Registry – Referencing Requires Explicit Permission
  • SANS IOT Internet of Things Reading Room
  • What creates the threads that we can assert?

Ten normative references

  • Benchmark contains both descriptive information and structural information
  • Group item that can hold other items
  • Item three types of items: <xccdf:Group>, <xccdf:Rule> and <xccdf:Value>
  • Model suggested scoring model for an <xccdf:Benchmark>
  • Profile element is named tailoring for an <xccdf:Benchmark>
  • Rule the description for a single item of guidance or constraint. <xccdf:Rule> elements form the basis for testing a target platform for benchmark compliance
  • Status acceptance status of an element with an optional date attribute, which signifies the date of the status change
  • Tailoring element holds one or more <xccdf:Profile> elements-records additional benchmark tailoring
  • TestResult element encapsulates the results of a single application of an <xccdf:Benchmark> to a single target platform

Value a named parameter that can be substituted into properties of other elements within the <xccdf:Benchmark>

  • Control Correlation Identifiers CCI
  • http://iase.disa.mil/stigs/cci/Pages/index.aspx
  • The Control Correlation Identifier (CCI) provides a standard identifier and description for each of the singular, actionable statements that comprise an IA control or IA best practice.
  • CCI bridges the gap between high-level policy expressions and low-level technical implementations. CCI allows a security requirement that is expressed in a high-level policy framework to be decomposed and explicitly associated with the low-level security setting(s) that must be assessed to determine compliance with the objectives of that specific security control.
  • This ability to trace security requirements from their origin (e.g., regulations, IA frameworks) to their low-level implementation allows organizations to readily demonstrate compliance to multiple IA compliance frameworks.
  • CCI also provides a means to objectively roll up and compare related compliance assessment results across disparate technologies.
  • Open Vulnerability and Assessment Language (OVAL) 
  • OVAL® is an information security community effort to standardize how to assess and report machine state of computer systems.
  • Tools and services that use OVAL for the three steps of system assessment — representing system information, expressing specific machine states, and reporting the results of an assessment — provide enterprises with accurate, consistent, and actionable information so they may improve their security.
  • Possible Future Integration is working with MITRE ATT&CK

Interfaces for Working with ATT&CK: There are two different ways for you to access the ATT&CK content:

  • ATT&CK expressed in STIX 2.0 GitHub repository: There are a few different ways to interact with the ATT&CK content (repo). Python, the best way is to utilize cti-python-stix2. The USAGE doc in the repo helps. Since STIX 2.0 is JSON, that library is the programming language of choice to interact with the raw content, such as the full set of Enterprise ATT&CK content found here.
  • TAXII Server: The TAXII server stays up to date with the content found in our GitHub repository, so consumers access the ATT&CK content there. As the TAXII Server release blog post states, consumers use the cti-python-stix2and cti-taxii-client to get the ATT&CK content from the TAXII server.

 

Main Menu