CyberSecurity 1 day (7h)

IEC 81001-5-1 (Medical Device Cybersecurity)

Cybersecurity for medical devices: apply IEC 81001-5-1 security activities across the health-software life cycle.

Course Description

This IEC 81001-5-1 training covers the cybersecurity activities required across the lifecycle of health software and medical device software, alongside IEC 62304 and ISO 14971.

Pedagogical Objectives

By the end of this course, participants will be able to:

  • Position cybersecurity within the medical ecosystem and understand the applicable regulatory requirements.
  • Conduct a cybersecurity risk assessment.
  • Implement the requirements of IEC 81001-5-1.
  • Plan the detailed actions and verifications for each part of the medical-device life cycle.
  • Select the tools required to conduct code audits.
  • Plan the response to a cybersecurity incident.

Course Program

  • Introduction and reminder of basic concepts.
  • Regulatory and normative context of medical-device cybersecurity: EU and US regulations; overview of applicable standards; requirements of IEC 62304 and IEC 60601-1.
  • IEC 81001-5-1: required processes and activities.
  • IEC 62443 & IEC 60601-4-5: safety levels and fundamental requirements; security capabilities (IEC 62443-4-2); application to medical devices (IEC 60601-4-5).
  • Collateral standards for connected medical devices: IEC 80001-1 and associated technical reports.
  • Security risk management: risk assessment / ISO 14971; threat modeling; vulnerability evaluation / CVSS.
  • Secure development process: Secure-by-Design; use of third-party software (SOUP, OTS); software cybersecurity audit tools.
  • Cybersecurity incident response; Q&A and conclusion.

Request Information on IEC 81001-5-1 (Medical Device Cybersecurity)

Fill out the form below to request information on this training or a custom session for your team.