Enerxen

Software Security Standards

November 20th, 2023 – Mitchell Gorthy

FDA recognizes three new international medical device software security standards

The FDA and CDRH recognized three new medical device software security standards. ANSI/AMMI 2700-2-1 and ANSI/AMMI SW96 developed by American National Standards Institute (ANSI) and The Association for the Advancement of Medical Instrumentation (AAMI) are among them. ISO/IEC/IEEE 29119-1 from The International Standards Organization (ISO), the International Electrotechnical Commission (IEC), and the Institute of Electrical and Electronics Engineers Standards Association (IEEE) is the other. The standards emphasize a total product lifecycle (TPLC) approach to medical device cybersecurity, data logging, and software testing. Consequently, they ensure transparent and consistent expectations for device manufacturers during reviews.

ANSI/AMMI 2700-2-1

To begin, ANSI/AAMI 2700-2-1, a part of the AAMI 2700 standards, aims for safe integrated clinical environments (ICE)(ANSI/AAMI 2700-1). Primarily, It targets medical device manufacturers, platform developers, and system integrators. It specifies data recording, storage, playback for safety, quality assurance, and forensic analysis. Furthermore, it ensures safe device interoperability through ICE data logging system requirements. FDA echoed ANSI’s comments and said that the standard addresses general functional, performance, security, and interoperability requirements used in data logging systems used in ICE environments. The agency added that data loggers are important to maintaining and improving basic safety and performance in ICE systems by allowing stakeholders to run forensic analyses.

ANSI/AMMI SW96Security Risk Management for Device Manufacturers

Regarding the following standard, ANSI/AMMI SW96 delineates security risk management methods for medical devices. It aligns with ISO 14971, complementing AAMI TIR57 and AAMI TIR97. The standard specifies requirements and guidance for sponsors adopting a TPLC approach to manage medical devices involving software vulnerabilities, as stated by the FDA. The agency highlights multiple areas where this standard ensures device security: identifying threats, vulnerabilities, and implementing necessary controls. FDA notes its applicability across a device’s entire life cycle, covering design, production, and post-production phases. Additionally, FDA mentions that milestones like End of Support (EOS) and End of Guaranteed Support (EOGS) might vary based on market and jurisdictional factors during the post-production phase.

ISO/IEC/IEEE 29119-1Software Testing

To conclude, ISO highlights that ISO/IEC/IEEE 29119-1 comprises globally accepted standards applicable to various software-inclusive products. Hence, excessive software testing might not be practical in most instances. Instead, the standard prescribes a risk-based sampling method for comprehensive yet efficient testing. According to ISO, the standard recommends test plans and strategies within a risk-based testing framework, forming the basis for test prioritization, test levels, types, and design techniques.

How can Enerxen help?

As you navigate the evolving FDA-recognized software security standards, Enerxen guides you through implementation. Our tailored expertise ensures seamless safety measures, like data recording and storage, essential for clinical environments. We actively assist in adopting a comprehensive approach to managing security risks and efficient software testing strategies. This empowers your compliance across diverse product lifecycle stages, ensuring regulatory alignment.

Contact us today to get started towards the path of regulatory success with a complimentary consultation with one of our seasoned experts. We will work closely with you to create a personalized strategy that aligns with your product. Find a more in-depth overview to our service what we do here.

Related Links

ANSI/AAMI 2700-2-1:2022

ANSI/AAMI SW96:2023

ISO/IEC/IEEE 29119-1:2022