Solicitation Attachment B - NEMA MDS2 Worksheet.xlsx

XLSX spreadsheet 44 KB Posted

Attached to
Nationwide Infusion Pump Requirement Federal contract opportunity
Solicitation number
36C24125R0070_1
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 1

About this file

The file is a NEMA MDS2 Worksheet, a comprehensive medical device security assessment form designed to evaluate the cybersecurity characteristics of medical devices. The extensive spreadsheet contains detailed sections covering multiple security domains including personally identifiable information management, authentication mechanisms, malware protection, network connectivity, software updates, data encryption, remote service capabilities, and physical security controls. The worksheet is structured to systematically document a medical device's security features across various international standards including IEC TR 80001-2-2:2012, NIST SP 800-53 Rev. 4, ISO 27002:2013, and others, with specific focus on healthcare technology security considerations.

The form requires manufacturers to provide granular details about device security capabilities, such as user authentication methods, audit logging, emergency access features, data integrity mechanisms, third-party component management, software bill of materials, and potential vulnerabilities. Key areas of assessment include node authentication, transmission confidentiality, system hardening, access controls, encryption capabilities, remote service protocols, and potential security update processes. The comprehensive nature of the worksheet indicates a rigorous approach to evaluating medical device cybersecurity, ensuring potential users can thoroughly understand a device's security posture before implementation.

View the file

Other files for this federal contract opportunity

Other files attached to Nationwide Infusion Pump Requirement, newest first.
File Type Posted
36C24125R0070 0003.docx DOCX document
Amendment 0003 Attachment - Questions and Answers.xlsx XLSX spreadsheet
36C24125R0070 0002.pdf PDF
36C24125R0070 0001.pdf PDF
Amendment 0001 Attachment - Revised Statement of Work.pdf PDF
Amendment 0001 Attachment - Questions and Answers.xlsx XLSX spreadsheet
Amendment 0001 Attachment - Revised FAR 52.212-1 Instructions to Offerors.pdf PDF
Amendment 0001 Attachment - Revised FAR 52.212-2 Evaluation.pdf PDF
Solicitation Attachment A - Pricing Worksheet.xlsx XLSX spreadsheet
Solicitation Attachment C - VA Directive 6550 Appendix A.pdf PDF
36C24125R0070.pdf PDF
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

mds2-form

Manufacturer Disclosure Statement for Medical Device Security -- MDS2
________________________
Question IDQuestionSee noteIEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
DOC-1Manufacturer Name________
DOC-2Device Description________
DOC-3Device Model________
DOC-4Document ID________
DOC-5Manufacturer Contact Information________
DOC-6Intended use of device in network-connected environment:________
DOC-7Document Release Date________
DOC-8Coordinated Vulnerability Disclosure: Does the manufacturer have a vulnerability disclosure program for this device?________
DOC-9ISAO: Is the manufacturer part of an Information Sharing and Analysis Organization?________
DOC-10Diagram: Is a network or data flow diagram available that indicates connections to other system components or expected external resources?__
DOC-11SaMD: Is the device Software as a Medical Device (i.e. software-only, no hardware)?________
DOC-11.1Does the SaMD contain an operating system?________
DOC-11.2Does the SaMD rely on an owner/operator provided operating system?________
DOC-11.3Is the SaMD hosted by the manufacturer?______
DOC-11.4Is the SaMD hosted by the customer?________

Yes, No, N/A, or

See NoteNote #
MANAGEMENT OF PERSONALLY IDENTIFIABLE INFORMATIONIEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
MPII-1Can this device display, transmit, store, or modify personally identifiable information (e.g. electronic Protected Health Information (ePHI))?________AR-2A.15.1.4
MPII-2Does the device maintain personally identifiable information?______AR-2A.15.1.4
MPII-2.1Does the device maintain personally identifiable information temporarily in volatile memory (i.e., until cleared by power-off or reset)?________AR-2A.15.1.4
MPII-2.2Does the device store personally identifiable information persistently on internal media?________
MPII-2.3Is personally identifiable information preserved in the device’s non-volatile memory until explicitly erased?________
MPII-2.4Does the device store personally identifiable information in a database?________
MPII-2.5Does the device allow configuration to automatically delete local personally identifiable information after it is stored to a long term solution?________AR-2A.15.1.4
MPII-2.6Does the device import/export personally identifiable information with other systems (e.g., a wearable monitoring device might export personally identifiable information to a server)?________AR-2A.15.1.4
MPII-2.7Does the device maintain personally identifiable information when powered off, or during power service interruptions?________AR-2A.15.1.4
MPII-2.8Does the device allow the internal media to be removed by a service technician (e.g., for separate destruction or customer retention)?________
MPII-2.9Does the device allow personally identifiable information records be stored in a separate location from the device’s operating system (i.e. secondary internal drive, alternate drive partition, or remote storage location)?______AR-2A.15.1.4
MPII-3Does the device have mechanisms used for the transmitting, importing/exporting of personally identifiable information?________AR-2A.15.1.4
MPII-3.1Does the device display personally identifiable information (e.g., video display, etc.)?________AR-2A.15.1.4
MPII-3.2Does the device generate hardcopy reports or images containing personally identifiable information?________AR-2A.15.1.4
MPII-3.3Does the device retrieve personally identifiable information from or record personally identifiable information to removable media (e.g., removable-HDD, USB memory, DVD-R/RW,CD-R/RW, tape, CF/SD card, memory stick, etc.)?________AR-2A.15.1.4
MPII-3.4Does the device transmit/receive or import/export personally identifiable information via dedicated cable connection (e.g., RS-232, RS-423, USB, FireWire, etc.)?________AR-2A.15.1.4
MPII-3.5Does the device transmit/receive personally identifiable information via a wired network connection (e.g., RJ45, fiber optic, etc.)?________AR-2A.15.1.4
MPII-3.6Does the device transmit/receive personally identifiable information via a wireless network connection (e.g., WiFi, Bluetooth, NFC, infrared, cellular, etc.)?________AR-2A.15.1.4
MPII-3.7Does the device transmit/receive personally identifiable information over an external network (e.g., Internet)?________AR-2A.15.1.4
MPII-3.8Does the device import personally identifiable information via scanning a document?______
MPII-3.9Does the device transmit/receive personally identifiable information via a proprietary protocol?______
MPII-3.10Does the device use any other mechanism to transmit, import or export personally identifiable information?________AR-2A.15.1.4
Management of Private Data notes:AR-2A.15.1.4
AUTOMATIC LOGOFF (ALOF)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The device's ability to prevent access and misuse by unauthorized users if device is left idle for a period of time.
ALOF-1Can the device be configured to force reauthorization of logged-in user(s) after a predetermined length of inactivity (e.g., auto-logoff, session lock, password protected screen saver)?________Section 5.1, ALOFAC-12None
ALOF-2Is the length of inactivity time before auto-logoff/screen lock user or administrator configurable?________Section 5.1, ALOFAC-11A.11.2.8, A.11.2.9
AUDIT CONTROLS (AUDT)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability to reliably audit activity on the device.
AUDT-1Can the medical device create additional audit logs or reports beyond standard operating system logs?________Section 5.2, AUDTAU-1A.5.1.1, A.5.1.2, A.6.1.1, A.12.1.1, A.18.1.1, A.18.2.2
AUDT-1.1Does the audit log record a USER ID?________
AUDT-1.2Does other personally identifiable information exist in the audit trail?Section 5.2, AUDTAU-2None
AUDT-2Are events recorded in an audit log? If yes, indicate which of the following events are recorded in the audit log:________Section 5.2, AUDTAU-2None
AUDT-2.1Successful login/logout attempts?________Section 5.2, AUDTAU-2None
AUDT-2.2Unsuccessful login/logout attempts?________Section 5.2, AUDTAU-2None
AUDT-2.3Modification of user privileges?________Section 5.2, AUDTAU-2None
AUDT-2.4Creation/modification/deletion of users?________Section 5.2, AUDTAU-2None
AUDT-2.5Presentation of clinical or PII data (e.g. display, print)?________Section 5.2, AUDTAU-2None
AUDT-2.6Creation/modification/deletion of data?________Section 5.2, AUDTAU-2None
AUDT-2.7Import/export of data from removable media (e.g. USB drive, external hard drive, DVD)?________Section 5.2, AUDTAU-2None
AUDT-2.8Receipt/transmission of data or commands over a network or point-to-point connection?________Section 5.2, AUDTAU-2None
AUDT-2.8.1Remote or on-site support?________Section 5.2, AUDTAU-2None
AUDT-2.8.2Application Programming Interface (API) and similar activity?________Section 5.2, AUDTAU-2None
AUDT-2.9Emergency access?________Section 5.2, AUDTAU-2None
AUDT-2.10Other events (e.g., software updates)?________Section 5.2, AUDTAU-2None
AUDT-2.11Is the audit capability documented in more detail?________Section 5.2, AUDTAU-2None
AUDT-3Can the owner/operator define or select which events are recorded in the audit log?Section 5.2, AUDTAU-2None
AUDT-4Is a list of data attributes that are captured in the audit log for an event available?________Section 5.2, AUDTAU-2None
AUDT-4.1Does the audit log record date/time?________Section 5.2, AUDTAU-2None
AUDT-4.1.1Can date and time be synchronized by Network Time Protocol (NTP) or equivalent time source?________Section 5.2, AUDTAU-2None
AUDT-5Can audit log content be exported?________Section 5.2, AUDTAU-2None
AUDT-5.1Via physical media?________
AUDT-5.2Via IHE Audit Trail and Node Authentication (ATNA) profile to SIEM?________
AUDT-5.3Via Other communications (e.g., external service device, mobile applications)?________
AUDT-5.4Are audit logs encrypted in transit or on storage media?________
AUDT-6Can audit logs be monitored/reviewed by owner/operator?________
AUDT-7Are audit logs protected from modification?________Section 5.2, AUDTAU-2None
AUDT-7.1Are audit logs protected from access?
AUDT-8Can audit logs be analyzed by the device?________Section 5.2, AUDTAU-2None
AUTHORIZATION (AUTH)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability of the device to determine the authorization of users.
AUTH-1Does the device prevent access to unauthorized users through user login requirements or other mechanism?________Section 5.3, AUTHIA-2A.9.2.1
AUTH-1.1Can the device be configured to use federated credentials management of users for authorization (e.g., LDAP, OAuth)?________Section 5.3, AUTHIA-2A.9.2.1
AUTH-1.2Can the customer push group policies to the device (e.g., Active Directory)?________Section 5.3, AUTHIA-2A.9.2.1
AUTH-1.3Are any special groups, organizational units, or group policies required?________Section 5.3, AUTHIA-2A.9.2.1
AUTH-2Can users be assigned different privilege levels based on 'role' (e.g., user, administrator, and/or service, etc.)?________Section 5.3, AUTHIA-2A.9.2.1
AUTH-3Can the device owner/operator grant themselves unrestricted administrative privileges (e.g., access operating system or application via local root or administrator account)?________Section 5.3, AUTHIA-2A.9.2.1
AUTH-4Does the device authorize or control all API access requests?________Section 5.3, AUTHIA-2A.9.2.1
AUTH-5Does the device run in a restricted access mode, or ‘kiosk mode’, by default?________
CYBER SECURITY PRODUCT UPGRADES (CSUP)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability of on-site service staff, remote service staff, or authorized customer staff to install/upgrade device's security patches.
CSUP-1Does the device contain any software or firmware which may require security updates during its operational life, either from the device manufacturer or from a third-party manufacturer of the software/firmware? If no, answer “N/A” to questions in this section.________
CSUP-2Does the device contain an Operating System? If yes, complete 2.1-2.4.________
CSUP-2.1Does the device documentation provide instructions for owner/operator installation of patches or software updates?________Y/NY/NY/N
CSUP-2.2Does the device require vendor or vendor-authorized service to install patches or software updates?________Y/NY/NY/N
CSUP-2.3Does the device have the capability to receive remote installation of patches or software updates?________Y/NY/NY/N
CSUP-2.4Does the medical device manufacturer allow security updates from any third-party manufacturers (e.g., Microsoft) to be installed without approval from the manufacturer?________Y/NY/NY/N
CSUP-3Does the device contain Drivers and Firmware? If yes, complete 3.1-3.4.________Y/NY/NY/N
CSUP-3.1Does the device documentation provide instructions for owner/operator installation of patches or software updates?________Y/NY/NY/N
CSUP-3.2Does the device require vendor or vendor-authorized service to install patches or software updates?________
CSUP-3.3Does the device have the capability to receive remote installation of patches or software updates?________Y/NY/NY/N
CSUP-3.4Does the medical device manufacturer allow security updates from any third-party manufacturers (e.g., Microsoft) to be installed without approval from the manufacturer?________Y/NY/NY/N
CSUP-4Does the device contain Anti-Malware Software? If yes, complete 4.1-4.4.________Y/NY/NY/N
CSUP-4.1Does the device documentation provide instructions for owner/operator installation of patches or software updates?________Y/NY/NY/N
CSUP-4.2Does the device require vendor or vendor-authorized service to install patches or software updates?________Y/NY/NY/N
CSUP-4.3Does the device have the capability to receive remote installation of patches or software updates?________Y/NY/NY/N
CSUP-4.4Does the medical device manufacturer allow security updates from any third-party manufacturers (e.g., Microsoft) to be installed without approval from the manufacturer?________
CSUP-5Does the device contain Non-Operating System commercial off-the-shelf components? If yes, complete 5.1-5.4.________Y/NY/NY/N
CSUP-5.1Does the device documentation provide instructions for owner/operator installation of patches or software updates?________Y/NY/NY/N
CSUP-5.2Does the device require vendor or vendor-authorized service to install patches or software updates?________Y/NY/NY/N
CSUP-5.3Does the device have the capability to receive remote installation of patches or software updates?________Y/NY/NY/N
CSUP-5.4Does the medical device manufacturer allow security updates from any third-party manufacturers (e.g., Microsoft) to be installed without approval from the manufacturer?________Y/NY/NY/N
CSUP-6Does the device contain other software components (e.g., asset management software, license management)? If yes, please provide details or refernce in notes and complete 6.1-6.4.________Y/NY/NY/N
CSUP-6.1Does the device documentation provide instructions for owner/operator installation of patches or software updates?________
CSUP-6.2Does the device require vendor or vendor-authorized service to install patches or software updates?________Y/NY/NY/N
CSUP-6.3Does the device have the capability to receive remote installation of patches or software updates?________Y/NY/NY/N
CSUP-6.4Does the medical device manufacturer allow security updates from any third-party manufacturers (e.g., Microsoft) to be installed without approval from the manufacturer?________Y/NY/NY/N
CSUP-7Does the manufacturer notify the customer when updates are approved for installation?________Y/NY/NY/N
CSUP-8Does the device perform automatic installation of software updates?________Y/NY/NY/N
CSUP-9Does the manufacturer have an approved list of third-party software that can be installed on the device?________Y/NY/NY/N
CSUP-10Can the owner/operator install manufacturer-approved third-party software on the device themselves?________
CSUP-10.1Does the system have mechanism in place to prevent installation of unapproved software?________
CSUP-11Does the manufacturer have a process in place to assess device vulnerabilities and updates?________Y/NY/NY/N
CSUP-11.1Does the manufacturer provide customers with review and approval status of updates?________Y/NY/NY/N
CSUP-11.2Is there an update review cycle for the device?________Y/NY/NY/N
Device SoftwareDevice FirmwareSecurity Addons
HEALTH DATA DE-IDENTIFICATION (DIDT)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability of the device to directly remove information that allows identification of a person.
DIDT-1Does the device provide an integral capability to de-identify personally identifiable information?________Section 5.6, DIDTNoneISO 27038
DIDT-1.1Does the device support de-identification profiles that comply with the DICOM standard for de-identification?________Section 5.6, DIDTNoneISO 27038
DATA BACKUP AND DISASTER RECOVERY (DTBK)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability to recover after damage or destruction of device data, hardware, software, or site configuration information.
DTBK-1Does the device maintain long term primary storage of personally identifiable information / patient information (e.g. PACS)?________
DTBK-2Does the device have a “factory reset” function to restore the original device settings as provided by the manufacturer?________Section 5.7, DTBKCP-9A.12.3.1
DTBK-3Does the device have an integral data backup capability to removable media?________Section 5.7, DTBKCP-9A.12.3.1
DTBK-4Does the device have an integral data backup capability to remote storage?
DTBK-5Does the device have a backup capability for system configuration information, patch restoration, and software restoration?
DTBK-6Does the device provide the capability to check the integrity and authenticity of a backup?________Section 5.7, DTBKCP-9A.12.3.1
EMERGENCY ACCESS (EMRG)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability of the device user to access personally identifiable information in case of a medical emergency situation that requires immediate access to stored personally identifiable information.
EMRG-1Does the device incorporate an emergency access (i.e. “break-glass”) feature?________Section 5.8, EMRGSI-17None
HEALTH DATA INTEGRITY AND AUTHENTICITY (IGAU)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
How the device ensures that the stored data on the device has not been altered or destroyed in a non-authorized manner and is from the originator.
IGAU-1Does the device provide data integrity checking mechanisms of stored health data (e.g., hash or digital signature)?________Section 5.9, IGAUSC-28A.18.1.3
IGAU-2Does the device provide error/failure protection and recovery mechanisms for stored health data (e.g., RAID-5)?________Section 5.9, IGAUSC-28A.18.1.3
MALWARE DETECTION/PROTECTION (MLDP)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability of the device to effectively prevent, detect and remove malicious software (malware).
MLDP-1Is the device capable of hosting executable software?________Section 5.10, MLDP
MLDP-2Does the device support the use of anti-malware software (or other anti-malware mechanism)? Provide details or reference in notes.________Section 5.10, MLDPSI-3A.12.2.1
MLDP-2.1Does the device include anti-malware software by default?________Section 5.10, MLDPCM-5A.9.2.3, A.9.4.5, A.12.1.2, A.12.1.4, A.12.5.1
MLDP-2.2Does the device have anti-malware software available as an option?________Section 5.10, MLDPAU-6A.12.4.1, A.16.1.2, A.16.1.4
MLDP-2.3Does the device documentation allow the owner/operator to install or update anti-malware software?________Section 5.10, MLDPCP-10A.17.1.2
MLDP-2.4Can the device owner/operator independently (re-)configure anti-malware settings?________Section 5.10, MLDPAU-2None
MLDP-2.5Does notification of malware detection occur in the device user interface?______
MLDP-2.6Can only manufacturer-authorized persons repair systems when malware has been detected?______
MLDP-2.7Are malware notifications written to a log?______
MLDP-2.8Are there any restrictions on anti-malware (e.g., purchase, installation, configuration, scheduling)?______
MLDP-3If the answer to MLDP-2 is NO, and anti-malware cannot be installed on the device, are other compensating controls in place or available?________Section 5.10, MLDPSI-2A.12.6.1, A.14.2.2, A.14.2.3, A.16.1.3
MLDP-4Does the device employ application whitelisting that restricts the software and services that are permitted to be run on the device?________Section 5.10, MLDPSI-3A.12.2.1
MLDP-5Does the device employ a host-based intrusion detection/prevention system?________Section 5.10, MLDPSI-4None
MLDP-5.1Can the host-based intrusion detection/prevention system be configured by the customer?________Section 5.10, MLDPCM-7A.12.5.1
MLDP-5.2Can a host-based intrusion detection/prevention system be installed by the customer?________Section 5.10, MLDP
NODE AUTHENTICATION (NAUT)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability of the device to authenticate communication partners/nodes.
NAUT-1Does the device provide/support any means of node authentication that assures both the sender and the recipient of data are known to each other and are authorized to receive transferred information (e.g. Web APIs, SMTP, SNMP)?________Section 5.11, NAUTSC-23None
NAUT-2Are network access control mechanisms supported (E.g., does the device have an internal firewall, or use a network connection white list)?________Section 5.11, NAUTSC-7A.13.1.1, A.13.1.3, A.13.2.1,A.14.1.3
NAUT-2.1Is the firewall ruleset documented and available for review?________
NAUT-3Does the device use certificate-based network connection authentication?________
CONNECTIVITY CAPABILITIES (CONN)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
All network and removable media connections must be considered in determining appropriate security controls. This section lists connectivity capabilities that may be present on the device.
CONN-1Does the device have hardware connectivity capabilities?________
CONN-1.1Does the device support wireless connections?________
CONN-1.1.1Does the device support Wi-Fi?________
CONN-1.1.2Does the device support Bluetooth?________
CONN-1.1.3Does the device support other wireless network connectivity (e.g. LTE, Zigbee, proprietary)?________
CONN-1.1.4Does the device support other wireless connections (e.g., custom RF controls, wireless detectors)?________
CONN-1.2Does the device support physical connections?________
CONN-1.2.1Does the device have available RJ45 Ethernet ports?________
CONN-1.2.2Does the device have available USB ports?________
CONN-1.2.3Does the device require, use, or support removable memory devices?________
CONN-1.2.4Does the device support other physical connectivity?________
CONN-2Does the manufacturer provide a list of network ports and protocols that are used or may be used on the device?________
CONN-3Can the device communicate with other systems within the customer environment?________
CONN-4Can the device communicate with other systems external to the customer environment (e.g., a service host)?________
CONN-5Does the device make or receive API calls?________
CONN-6Does the device require an internet connection for its intended use?________
CONN-7Does the device support Transport Layer Security (TLS)?________
CONN-7.1Is TLS configurable?
CONN-8Does the device provide operator control functionality from a separate device (e.g., telemedicine)?________
PERSON AUTHENTICATION (PAUT)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability to configure the device to authenticate users.
PAUT-1Does the device support and enforce unique IDs and passwords for all users and roles (including service accounts)?________Section 5.12, PAUTIA-2A.9.2.1
PAUT-1.1Does the device enforce authentication of unique IDs and passwords for all users and roles (including service accounts)?________Section 5.12, PAUTIA-2A.9.2.1
PAUT-2Is the device configurable to authenticate users through an external authentication service (e.g., MS Active Directory, NDS, LDAP, OAuth, etc.)?________Section 5.12, PAUTIA-5A.9.2.1
PAUT-3Is the device configurable to lock out a user after a certain number of unsuccessful logon attempts?________Section 5.12, PAUTIA-2A.9.2.1
PAUT-4Are all default accounts (e.g., technician service accounts, administrator accounts) listed in the documentation?________Section 5.12, PAUTSA-4(5)A.14.1.1, A.14.2.7, A.14.2.9, A.15.1.2
PAUT-5Can all passwords be changed?________Section 5.12, PAUT
PAUT-6Is the device configurable to enforce creation of user account passwords that meet established (organization specific) complexity rules?________Section 5.12, PAUTIA-2A.9.2.1
PAUT-7Does the device support account passwords that expire periodically?________
PAUT-8Does the device support multi-factor authentication?________
PAUT-9Does the device support single sign-on (SSO)?________Section 5.12, PAUTIA-2A.9.2.1
PAUT-10Can user accounts be disabled/locked on the device?________Section 5.12, PAUTIA-2A.9.2.1
PAUT-11Does the device support biometric controls?________Section 5.12, PAUTIA-2A.9.2.1
PAUT-12Does the device support physical tokens (e.g. badge access)?________
PAUT-13Does the device support group authentication (e.g. hospital teams)?________
PAUT-14Does the application or device store or manage authentication credentials?________
PAUT-14.1Are credentials stored using a secure method?________
PHYSICAL LOCKS (PLOK)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
Physical locks can prevent unauthorized users with physical access to the device from compromising the integrity and confidentiality of personally identifiable information stored on the device or on removable media
PLOK-1Is the device software only? If yes, answer “N/A” to remaining questions in this section.________Section 5.13, PLOKPE- 3(4)A.11.1.1, A.11.1.2, A.11.1.3
PLOK-2Are all device components maintaining personally identifiable information (other than removable media) physically secure (i.e., cannot remove without tools)?________Section 5.13, PLOKPE- 3(4)A.11.1.1, A.11.1.2, A.11.1.3
PLOK-3Are all device components maintaining personally identifiable information (other than removable media) physically secured behind an individually keyed locking device?________Section 5.13, PLOKPE- 3(4)A.11.1.1, A.11.1.2, A.11.1.3
PLOK-4Does the device have an option for the customer to attach a physical lock to restrict access to removable media?________Section 5.13, PLOKPE- 3(4)A.11.1.1, A.11.1.2, A.11.1.3
ROADMAP FOR THIRD PARTY COMPONENTS IN DEVICE LIFE CYCLE (RDMP)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
Manufacturer’s plans for security support of third-party components within the device’s life cycle.
RDMP-1Was a secure software development process, such as ISO/IEC 27034 or IEC 62304, followed during product development?________Section 5.14, RDMPCM-2None
RDMP-2Does the manufacturer evaluate third-party applications and software components included in the device for secure development practices?________Section 5.14, RDMPCM-8A.8.1.1, A.8.1.2
RDMP-3Does the manufacturer maintain a web page or other source of information on software support dates and updates?________Section 5.14, RDMPCM-8A.8.1.1, A.8.1.2
RDMP-4Does the manufacturer have a plan for managing third-party component end-of-life?________Section 5.14, RDMPCM-8A.8.1.1, A.8.1.2
SOFTWARE BILL OF MATERIALS (SBoM)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
A Software Bill of Material (SBoM) lists all the software components that are incorporated into the device being described for the purpose of operational security planning by the healthcare delivery organization. This section supports controls in the RDMP section.
SBOM-1Is the SBoM for this product available?________
SBOM-2Does the SBoM follow a standard or common method in describing software components?________
SBOM-2.1Are the software components identified?________
SBOM-2.2Are the developers/manufacturers of the software components identified?________
SBOM-2.3Are the major version numbers of the software components identified?________
SBOM-2.4Are any additional descriptive elements identified?________
SBOM-3Does the device include a command or process method available to generate a list of software components installed on the device?________
SBOM-4Is there an update process for the SBoM?________
SYSTEM AND APPLICATION HARDENING (SAHD)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The device's inherent resistance to cyber attacks and malware.CM-7A.12.5.1*
SAHD-1Is the device hardened in accordance with any industry standards?________Section 5.15, SAHDAC-17(2)/IA-3A.6.2.1, A.6.2.2, A.13.1.1, A.13.2.1, A.14.1.2/None
SAHD-2Has the device received any cybersecurity certifications?________Section 5.15, SAHDSA-12(10)A.14.2.7, A.15.1.1, A.15.1.2, A.15.1.3
SAHD-3Does the device employ any mechanisms for software integrity checking________
SAHD-3.1Does the device employ any mechanism (e.g., release-specific hash key, checksums, digital signature, etc.) to ensure the installed software is manufacturer-authorized?________
SAHD-3.2Does the device employ any mechanism (e.g., release-specific hash key, checksums, digital signature, etc.) to ensure the software updates are the manufacturer-authorized updates?________Section 5.15, SAHDCM-8A.8.1.1, A.8.1.2
SAHD-4Can the owner/operator perform software integrity checks (i.e., verify that the system has not been modified or tampered with)?________Section 5.15, SAHDAC-3A.6.2.2, A.9.1.2, A.9.4.1, A.9.4.4, A.9.4.5, A.13.1.1, A.14.1.2, A.14.1.3, A.18.1.3
SAHD-5Is the system configurable to allow the implementation of file-level, patient level, or other types of access controls?________Section 5.15, SAHDCM-7A.12.5.1*
SAHD-5.1Does the device provide role-based access controls?________Section 5.15, SAHDCM-7A.12.5.1*
SAHD-6Are any system or user accounts restricted or disabled by the manufacturer at system delivery?________Section 5.15, SAHDCM-8A.8.1.1, A.8.1.2
SAHD-6.1Are any system or user accounts configurable by the end user after initial configuration?________Section 5.15, SAHDCM-7A.12.5.1*
SAHD-6.2Does this include restricting certain system or user accounts, such as service technicians, to least privileged access?________Section 5.15, SAHDCM-7A.12.5.1*
SAHD-7Are all shared resources (e.g., file shares) which are not required for the intended use of the device disabled?________Section 5.15, SAHDCM-7A.12.5.1*
SAHD-8Are all communication ports and protocols that are not required for the intended use of the device disabled?________Section 5.15, SAHDSA-18None
SAHD-9Are all services (e.g., telnet, file transfer protocol [FTP], internet information server [IIS], etc.), which are not required for the intended use of the device deleted/disabled?________Section 5.15, SAHDCM-6None
SAHD-10Are all applications (COTS applications as well as OS-included applications, e.g., MS Internet Explorer, etc.) which are not required for the intended use of the device deleted/disabled?________Section 5.15, SAHDSI-2A.12.6.1, A.14.2.2, A.14.2.3, A.16.1.3
SAHD-11Can the device prohibit boot from uncontrolled or removable media (i.e., a source other than an internal drive or memory component)?________
SAHD-12Can unauthorized software or hardware be installed on the device without the use of physical tools?________
SAHD-13Does the product documentation include information on operational network security scanning by users?________
SAHD-14Can the device be hardened beyond the default provided state?________
SAHD-14.1Are instructions available from vendor for increased hardening?
SHAD-15Can the system prevent access to BIOS or other bootloaders during boot?
SAHD-16Have additional hardening methods not included in 2.3.19 been used to harden the device?________
SECURITY GUIDANCE (SGUD)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
Availability of security guidance for operator and administrator of the device and manufacturer sales and service.
SGUD-1Does the device include security documentation for the owner/operator?________Section 5.16, SGUDAT-2/PL-2A.7.2.2, A.12.2.1/A.14.1.1
SGUD-2Does the device have the capability, and provide instructions, for the permanent deletion of data from the device or media?________Section 5.16, SGUDMP-6A.8.2.3, A.8.3.1, A.8.3.2, A.11.2.7
SGUD-3Are all access accounts documented?________Section 5.16, SGUDAC-6,IA-2A.9.1.2, A.9.2.3, A.9.4.4, A.9.4.5/A.9.2.1
SGUD-3.1Can the owner/operator manage password control for all accounts?________
SGUD-4Does the product include documentation on recommended compensating controls for the device?________
HEALTH DATA STORAGE CONFIDENTIALITY (STCF)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability of the device to ensure unauthorized access does not compromise the integrity and confidentiality of personally identifiable information stored on the device or removable media.
STCF-1Can the device encrypt data at rest?________Section 5.17, STCFSC-28A.8.2.3
STCF-1.1Is all data encrypted or otherwise protected?
STCF-1.2Is the data encryption capability configured by default?
STCF-1.3Are instructions available to the customer to configure encryption?
STCF-2Can the encryption keys be changed or configured?________Section 5.17, STCFSC-28A.8.2.3
STCF-3Is the data stored in a database located on the device?________
STCF-4Is the data stored in a database external to the device?________
TRANSMISSION CONFIDENTIALITY (TXCF)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability of the device to ensure the confidentiality of transmitted personally identifiable information.
TXCF-1Can personally identifiable information be transmitted only via a point-to-point dedicated cable?________Section 5.18, TXCFCM-7A.12.5.1
TXCF-2Is personally identifiable information encrypted prior to transmission via a network or removable media?________Section 5.18, TXCFCM-7A.12.5.1
TXCF-2.1If data is not encrypted by default, can the customer configure encryption options?________
TXCF-3Is personally identifiable information transmission restricted to a fixed list of network destinations?________Section 5.18, TXCFCM-7A.12.5.1
TXCF-4Are connections limited to authenticated systems?________Section 5.18, TXCFCM-7A.12.5.1
TXCF-5Are secure transmission methods supported/implemented (DICOM, HL7, IEEE 11073)?________
TRANSMISSION INTEGRITY (TXIG)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
The ability of the device to ensure the integrity of transmitted data.
TXIG-1Does the device support any mechanism (e.g., digital signatures) intended to ensure data is not modified during transmission?________Section 5.19, TXIGSC-8A.8.2.3, A.13.1.1, A.13.2.1, A.13.2.3, A.14.1.2, A.14.1.3
TXIG-2Does the device include multiple sub-components connected by external cables?________
REMOTE SERVICE (RMOT)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
Remote service refers to all kinds of device maintenance activities performed by a service person via network or other remote connection.
RMOT-1Does the device permit remote service connections for device analysis or repair?________AC-17A.6.2.1, A.6.2.2, A.13.1.1, A.13.2.1, A.14.1.2
RMOT-1.1Does the device allow the owner/operator to initiative remote service sessions for device analysis or repair?________
RMOT-1.2Is there an indicator for an enabled and active remote session?________
RMOT-1.3Can patient data be accessed or viewed from the device during the remote session?________AC-17A.6.2.1, A.6.2.2, A.13.1.1, A.13.2.1, A.14.1.2
RMOT-2Does the device permit or use remote service connections for predictive maintenance data?________
RMOT-3Does the device have any other remotely accessible functionality (e.g. software updates, remote training)?________
OTHER SECURITY CONSIDERATIONS (OTHR)IEC TR 80001-2-2:2012NIST SP 800-53 Rev. 4ISO 27002:2013
NONE

Notes:

Note 1 Example note. Please keep individual notes to one cell. Please use separate notes for separate information

ACME ABC123 1/1/2020

File details come from the government source that posted it. Updated .