CSA Official Press Release
Published 11/09/2021
New Cloud Security Alliance Guidance Provides Framework for Protecting Critical Healthcare Systems While Taking Risk to Patient Safety Into Account
Paper from IoT Working Group highlights the importance of not treating medical device incident response as a one-size-fits-all
SEATTLE – Nov. 9, 2021 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today released the CSA Medical Device Incident Response Playbook, which establishes a framework to ensure that cybersecurity not only protects critical healthcare systems and data but does so without negatively impacting patient safety.
Aimed at healthcare delivery organizations’ (HDO) cybersecurity staff and clinical leadership, as well as medical device manufacturers and related service providers who play a role in supporting HDO incident response processes, the paper highlights the importance of not treating medical device incident response as a one-size-fits-all process and of incorporating a tiered approach that takes risks to patient safety into consideration.
Written by the CSA Internet of Thing (IoT) Working Group, the paper provides a way for healthcare delivery organizations (HDO) to initiate conversations on how to incorporate clinical risks into security processes and lays out a roadmap for responding to those cybersecurity incidents that impact medical or patient care devices in such a way that takes into account the clinical risks associated with disconnecting the device from the patient and/or the network.
“Medical devices play an integral role in patient care. There are scenarios where medical devices must remain available to continue treatment even after being compromised,” said Brian Russell, co-chair of the IoT Working Group and one of the paper’s authors. “Hospitals must design their systems to be resilient, and an incident response plan that takes clinical aspects into consideration is a foundational element for resilient health delivery operations.”
“This playbook takes the clinical aspects of medical device operations into account,” said Christopher Frenz, co-author of the paper. “The paper identifies seven distinct incident response classifications based on impact to the patient and/or hospital operations. These seven classifications each include distinct handling instructions designed to minimize the impact to patient care.”
The CSA Internet of Things (IoT) Working Group focuses on understanding the relevant use cases for IoT deployments and defining actionable guidance for security practitioners to secure their implementations. Those interested in participating in future research and initiatives involving the IoT are invited to join the working group.
Download the CSA Medical Device Incident Response Playbook now.
About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA's activities, knowledge, and extensive network benefit the entire community impacted by cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.
About Cloud Security Alliance
The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.
For press inquiries, email Zenobia Godschalk of ZAG Communications or reach her by phone at 650.269.8315.