FDA Postmarket Guidance for Medical Devices

Jurisdiction
United States
Region
North America
Requirement
Recommended
Organization
FDA
Provision
Sec. V(B), VII
Applies to
Medical device manufacturers
Date
December 2016
Description

Section V(B): Manufacturers should implement "Cybersecurity Risk Management Programs" that include "adopting a coordinated vulnerability disclosure policy and practice." Since the rule was published in 2016, it suggests that manufacturers make use of the ISO/IEC 29147:2014 (Information Technology - Security Techniques - Vulnerability Disclosure) Standard, which has since been replaced by a new version in 2018. 

Section VII: Manufacturers should "adopt a coordinated vulnerability disclosure policy and practice that includes acknowledging receipt of the initial vulnerability report to the vulnerability submitter