The European Committee for Standardization is one of three European Standardization Organizations (together with CENELEC and ETSI) that have been officially recognized by the European Union and by the European Free Trade Association (EFTA) as being responsible for developing and defining voluntary standards at European level.
- |
Reference | EN ISO/IEEE 11073-40102:2022 |
---|---|
Title | Health informatics - Device interoperability - Part 40102: Foundational - Cybersecurity - Capabilities for mitigation (ISO/IEEE 11073-40102:2022) |
Work Item Number | 00251373 |
Abstract/Scope | Within the context of secure plug-and-play interoperability, cybersecurity is the process and capability of preventing unauthorized access or modification, misuse, denial of use, or the unauthorized use of information that is stored on, accessed from, or transferred to and from a PHD/PoCD. The capability part of cybersecurity is information security controls related to both digital data and the relationships to safety and usability. For PHDs/PoCDs, this standard defines a security baseline of application layer cybersecurity mitigation techniques for certain use cases or for times when certain criteria are met. This standard provides a scalable information security toolbox appropriate for PHD/PoCD interfaces, which fulfills the intersection of requirements and recommendations from National Institute of Standards and Technology (NIST) and the European Network and Information Security Agency (ENISA). This standard maps to the NIST cybersecurity framework [B15]; IEC TR 80001-2-2 [B8]; and the Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE) classification scheme. The mitigation techniques are based on the extended CIA triad (Clause 4) and are described generally to allow manufacturers to determine the most appropriate algorithms and implementations. |
Status |
Published
|
Reference Document |
ISO/IEEE 11073-40102:2022 (EQV)
|
date of Availability (DAV) | 2022-03-30 |
ICS | 35.240.80 - IT applications in health care technology |
A-Deviation(s) | |
Special National Condition(s) |
Directive(s) | |
---|---|
Mandate(s) | |
Citation in OJEU |
date of Ratification (DOR) (1) | 2022-03-13 |
---|---|
date of Availability (DAV) (2) | 2022-03-30 |
date of Announcement (DOA) (3) | 2022-06-30 |
date of Publication (DOP) (4) | 2022-09-30 |
date of Withdrawal (DOW) (5) | 2022-09-30 |
Supersedes | |
---|---|
Superseded by | |
Normative reference (6) |
NIST FIPS 197
NIST SP 800-38D |
Sales Points |
![]() |
(1) Date of ratification (dor) date when the Technical Board notes the approval of an EN (and HD for CENELEC), from which time the standard may be said to be approved
(2) Date of availability (dav) date when the definitive text in the official language versions of an approved CEN/CENELEC publication is distributed by the Central Secretariat
(3) Date of announcement (doa) latest date by which the existence of an EN (and HD for CENELEC), a TS or a CWA has to be announced at national level
(4) Date of publication (dop) latest date by which an EN has to be implemented at national level by publication of an identical national standard or by endorsement
(5) Date of withdrawal (dow) latest date by which national standards conflicting with an EN (and HD for CENELEC) have to be withdrawn
(6) This list of normative references is purely indicative. The only official list of normative reference is the list of the published standard.
In the case of undated standard, a link to the last dated version is provided.
In the case of series, a link to each standard identified in the series is provided.
We also invite you to check (via the website) whether corrigenda and/or amendments shall be read in conjunction with the main standard.