Forum Diskusi dan Komunitas Online

Full Version: How Does EU MDR Penetration Testing Identify Risks in SaMD and Class II/III Devices?
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Preparing a medical device to meet the EU MDR requirements can be difficult in some cases. It can be challenging when cybersecurity testing doesn’t cover its complete attack surface. The vulnerabilities may not be known until the APIs, cloud services, mobile apps, wireless interfaces, firmware, and hardware are tested. EU MDR Penetration testing makes it possible to identify risks in SaMD and Class II/III medical devices.

Penetration testing is more than just vulnerability scanning because it involves attacking the medical devices and their network components. Testers perform manual testing to simulate attacks, including exploit testing, authentication checks, protocol fuzzing, and firmware analysis. 

In this guide, we will discuss how EU MDR penetration testing is performed to uncover vulnerabilities. We will also discuss penetration testing for Software as a Medical Device (SaMD) and Class II/III medical devices. We will cover what needs to be done to comply with regulations.

Key Takeaways
  • The EU MDR penetration testing includes the entire attack surface of connected medical devices.
  • Penetration testing uses automated scanning along with manual exploitation and security testing.
  • Software as Medical Device testing includes apps, APIs, cloud, and AI, and Class II/III devices include firmware, wireless, and hardware testing.
  • Findings are assessed for their impact on device safety, functionality, data, and integrity.
  • The test results should comply with ISO 14971 risk management and applicable GSPRs.
  • Vulnerabilities should be fixed and retested to ensure that security validation is complete.
  • Post-market surveillance ensures continued security of devices as vulnerabilities emerge and software changes are made.
What Is EU MDR Compliance for Connected Devices?

EU MDR compliance for connected devices means it is necessary to satisfy those safety, security, and risk management criteria. The criteria should be relevant to the software, networks, and connectivity of the device during its entire lifecycle.

For connected medical devices, this includes the assessment of cybersecurity risks and the protection of data and functionality. It also covers documentation of security measures and vulnerability management after deployment of the device. Such requirements apply to medical devices utilising cloud services, application programming interfaces (APIs), mobile applications, wireless communication, or other connected components.

The objective is to ensure that any cybersecurity problem does not affect the safety or performance of the device or any personal data collected by it.

Source: https://qualysec.com/eu-mdr-penetration-testing/