Označení normy: | ČSN EN ISO/IEEE 11073-40101 |
Třídící znak: | 980014 |
Počet stran: | 60 |
Vydáno: | 01.10.2022 |
Harmonizace: | Norma není harmonizována |
Katalogové číslo: | 515150 |
Popis
ČSN EN ISO/IEEE 11073-40101
For Personal Health Devices (PHDs) and Point-of-Care Devices (PoCDs), an iterative, systematic, scalable, and auditable approach to identification of cybersecurity vulnerabilities and estimation of risk is defined by this standard. The standard presents one approach to iterative vulnerability assessment that uses the Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE) classi-fication scheme and the embedded Common Vulnerability Scoring System (eCVSS). The assessment includes system context, systém decomposition, pre-mitigation scoring, mitigation, and post-mitigation scoring and itera-tes until the remaining vulnerabilities are reduced to an acceptable level of risk.