CyberSecurity 1 day (7h)

IEC 81001-5-1 (Medical Device Cybersecurity)

Cybersecurity for medical devices: apply IEC 81001-5-1 security activities across the health-software life cycle.

Course Description

This IEC 81001-5-1 training covers the cybersecurity activities required across the lifecycle of health software and medical device software, alongside IEC 62304 and ISO 14971.

What the IEC 81001-5-1 training covers

The course covers the IEC 81001-5-1 security lifecycle, security requirements and risk management, secure design and implementation practices, verification and security testing, handling of SOUP and third-party components, and vulnerability and update management in the post-market phase.

Who should attend

Medical-device and health-software engineers, product security, quality and regulatory staff developing or assessing secure health software.

What you will learn

By the end, participants understand how IEC 81001-5-1 integrates security into the health software lifecycle and can plan the required security activities and evidence.

Format and delivery

This course is delivered on-site or remotely by ISIT engineers and can be tailored to your team’s protocols, standards and experience level. Contact us to build a programme around your project.

Pedagogical Objectives

By the end of this course, participants will be able to:

  • Position cybersecurity within the medical ecosystem and understand the applicable regulatory requirements.
  • Conduct a cybersecurity risk assessment.
  • Implement the requirements of IEC 81001-5-1.
  • Plan the detailed actions and verifications for each part of the medical-device life cycle.
  • Select the tools required to conduct code audits.
  • Plan the response to a cybersecurity incident.

Course Program

  • Introduction and reminder of basic concepts.
  • Regulatory and normative context of medical-device cybersecurity: EU and US regulations; overview of applicable standards; requirements of IEC 62304 and IEC 60601-1.
  • IEC 81001-5-1: required processes and activities.
  • IEC 62443 & IEC 60601-4-5: safety levels and fundamental requirements; security capabilities (IEC 62443-4-2); application to medical devices (IEC 60601-4-5).
  • Collateral standards for connected medical devices: IEC 80001-1 and associated technical reports.
  • Security risk management: risk assessment / ISO 14971; threat modeling; vulnerability evaluation / CVSS.
  • Secure development process: Secure-by-Design; use of third-party software (SOUP, OTS); software cybersecurity audit tools.
  • Cybersecurity incident response; Q&A and conclusion.

Register for IEC 81001-5-1 (Medical Device Cybersecurity)

Fill out the form below to register for this training or request a custom session for your team.