APRIL - 4 - 2019ENTERPRISE SECURITY| | 19Establishing Best Practices for a Comprehensive Risk-based Product Security ProgramBy Michael McNeil, Global Product Security & Services Officer, Philipsne of the more critical challenges facing medical device manufacturers and their customers today is to ensure that all products and solutions can withstand cyber attacks. The protection of customer networks and private patient health data is of utmost importance. With a flourishing digital revolution and connected ecosystem, it is clear that to meet these challenges manufacturers must take a strategic and integrated view of product security and establish a comprehensive risk-based security program. To address complex and growing best practice security needs, as well as regulatory and legal compliance requirements, internal entities charged with managing product security must also be charged with designing and monitoring mitigation structures and strategies. This entails creation of policies, procedures, and processes for safe and effective deployment of technology solutions. Additionally, this requirement calls for notification and management of incident response through monitoring of deployed technology solutions.Key goals and drivers include:·Prevent unauthorized access of medical devices and patient information·Prevent compromise or loss of patient data·Ensure medical device functional integrity and services availability to enable safe and reliable patient care·Enable up-to-date security patching to remediate unsecure systems and vulnerabilities·Integrate security compliance controls into product software development processesDemands from customers and patients for accurate and accessible data must be balanced with stringent requirements for the security of that data. Medical device manufacturers should seek to collaborate with industry stakeholders and establish long-term strategies for the lifecycle management of their products.Core Elements of a Comprehensive Risk-based Security Program In a connected, interoperable healthcare ecosystem the potential for exposure to vulnerabilities and attack is significant. This reality prompts Philips to devote extensive resources to mitigate such threats. Years of advancing innovation and product security capabilities has lead Philips to embody five essential elements of a successful product security program.1.Governance2.Testing3.Coordinated vulnerability disclosure4.Software bill of materials 5.Maturity roadmapGovernanceAlignment of executive leadership within the organization secures the `buy-in' necessary to move forward successfully. This in-house team provides oversight throughout the course of program development. Coordinating the efforts of external players across the cyber security ecosystem (customers, vendors, regulators, standards development organizations, industry groups and security researchers, among others) by entering into ongoing dialogue is extremely productive in refining program thinking and execution, as well as building key relationships.CXO INSIGHTSO
<
Page 9 |
Page 11 >