What the FDA Wants in Security Architecture Views for Devices | Ep. 29
Key Takeaways
The FDA requires medical device manufacturers to submit four specific security architecture views
the Global System View, the Updateability and Patchability View, the Multi-Patient Harm View, and Secure Use Case Views.
The 'Global System View' is crucial for establishing the entire scope of the device
including hardware, software, cloud components, and the often-overlooked update infrastructure.
A device's 'Updateability and Patchability View' is a key focus for regulators
as it demonstrates how the product will be securely maintained and protected against new vulnerabilities throughout its lifecycle.
The 'Multi-Patient Harm View' requires an analysis of how a single security flaw could scale to...
The 'Multi-Patient Harm View' requires an analysis of how a single security flaw could scale to affect a large number of patients, which is especially relevant for networked devices and cloud-based systems.
The 'Secure Use Case View,' often the most difficult
involves mapping security controls to every function and state of the device, essentially answering how security is addressed for everything the device can do.
A practical approach to creating Secure Use Case Views is to start with the device's functional...
A practical approach to creating Secure Use Case Views is to start with the device's functional requirements and build corresponding security requirements for each function.
Episode Summary
In this episode of the Med Device Cyber Podcast, host Christian Espinosa and guest Trevor Slattery from Blue Goat Cyber delve into the critical topic of device security architecture, specifically focusing on the four security architecture views required by the FDA for medical device premarket submissions. They provide a detailed breakdown of these views, which are often misunderstood by manufacturers, and explain how properly addressing them is essential for both regulatory compliance and building a secure product from the ground up. The discussion begins by emphasizing the need for a comprehensive understanding of what constitutes a 'device,' which extends beyond physical hardware to include all associated software, mobile apps, cloud components, and even the update infrastructure. They then explore each of the four FDA-defined security architecture views in detail. First is the 'Global System View,' which serves as the foundation for all other security analyses. This view requires manufacturers to clearly define the entire scope and boundary of their device and its ecosystem, outlining all internal components, data flows, and external connections. A common failure point highlighted is neglecting to include the update infrastructure within this scope. Second, they discuss the 'Updateability and Patchability View,' stressing its importance in the context of the total product lifecycle. This view documents how a device will receive secure software updates and patches to address vulnerabilities discovered post-market. They note that this is a major area of concern for the FDA, given the risk of supply chain attacks. The third view is the 'Multi-Patient Harm View,' which analyzes scenarios where a single vulnerability or compromise could impact multiple devices or patients simultaneously, such as a breach of a shared cloud server or the exploitation of hardcoded credentials across a fleet of devices. Finally, they tackle the 'Secure Use Case View,' which they identify as the most frequently misunderstood. This view acts as a catch-all, requiring a mapping of security controls to every specific function, state, and operational context of the device, from power-up and data transmission to user interactions and decommissioning. They advise using the device's functional requirements as a blueprint for building these secure use cases, effectively integrating security by design rather than retrofitting it as an afterthought. Throughout the episode, they offer practical advice and highlight common pitfalls, making a complex regulatory requirement more accessible to engineers and product managers in the medical device industry.
Chapters
- 0:00Hello and welcome back to the Med Device Cyber podcast
- 3:28Uh, typically when we're talking about architecture views, this is coming from
- 6:58So, I think that it the software documentation does lead in as
- 10:26I think you referred to the mobile app as a companion app
- 14:04That's further expand further expanded upon the updatable ability which I don't
- 17:29This is what each of these components is responsible for
- 20:51And I think that's why the FDA wants us to focus on
- 25:07So I I don't I don't think the FDA has that looks
Frequently Asked Questions
Quick answers drawn from this episode.
-
In this episode of the Med Device Cyber Podcast, host Christian Espinosa and guest Trevor Slattery from Blue Goat Cyber delve into the critical topic of device security architecture, specifically focusing on the four security architecture views required by the FDA for medical device premarket submissions.
-
The FDA requires medical device manufacturers to submit four specific security architecture views: the Global System View, the Updateability and Patchability View, the Multi-Patient Harm View, and Secure Use Case Views. The 'Global System View' is crucial for establishing the entire scope of the device, including hardware, software, cloud components, and...
-
The discussion begins by emphasizing the need for a comprehensive understanding of what constitutes a 'device,' which extends beyond physical hardware to include all associated software, mobile apps, cloud components, and even the update infrastructure. It's most useful for medical device manufacturers, cybersecurity engineers,...
-
The FDA requires medical device manufacturers to submit four specific security architecture views: the Global System View, the Updateability and Patchability View, the Multi-Patient Harm View, and Secure Use Case Views.
Listeners also asked
Quick answers pulled from related episodes.
-
What does Episode 62 cover about "Why Cybersecurity and Quality Are One and the Same"?
In this episode of The Med Device Cyber Podcast, guest Trevor Slattery is joined by Ashkon Rasooli, the Principal and Founder of Ingenious Solutions, a boutique consulting firm specializing in medical device software development. The conversation centers on the critical...
From Episode 062 · Why Cybersecurity and Quality Are One and the Same | Ep. 26 -
What does Episode 43 cover about "Unpacking Post-Market Management and Incident Response for Medical Devices"?
In this episode of the Med Device Cyber Podcast, host Christian Espinosa and guest Trevor Slattery of Blue Goat Cyber provide a comprehensive overview of post-market management and incident response in the context of medical device cybersecurity. They address the critical...
From Episode 043 · Unpacking Post-Market Management and Incident Response for Medical Devices | Ep. 23 -
What does Episode 18 cover about "FDA AI Guidance Explained: What It Means for Medical Device Cybersecurity"?
In this episode of The Med Device Cyber Podcast, host Christian Espinosa and guest Trevor Slattery of Blue Goat Cyber delve into the critical and timely topic of Artificial Intelligence (AI) in medical devices. They explore the unique cybersecurity risks that AI introduces into...
From Episode 018 · FDA AI Guidance Explained: What It Means for Medical Device Cybersecurity | Ep. 9
Show original YouTube description
Hosted by
More from your host
Other episodes diving into Christian's areas of focus.
More like this
Episodes covering similar ground.






