← All CCE Flashcard Decks

Medical Device Cybersecurity and Information Security Flashcards

7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Medical Device Cybersecurity and Information Security flashcards as text
  1. Which FDA guidance document specifically addresses cybersecurity considerations for medical devices in premarket submissions?

    Answer: Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions

    The FDA released 'Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions' to guide manufacturers on cybersecurity requirements during premarket submissions.

  2. What is the primary purpose of a Software Bill of Materials (SBOM) in medical device cybersecurity?

    Answer: To provide a complete inventory of all software components and dependencies in a medical device

    An SBOM provides a complete inventory of software components and dependencies, enabling identification and remediation of known vulnerabilities across the device's software supply chain.

  3. Which cybersecurity framework published by NIST is most commonly referenced for healthcare cybersecurity risk management?

    Answer: NIST Cybersecurity Framework (CSF)

    The NIST Cybersecurity Framework (CSF) provides a policy framework organized around Identify, Protect, Detect, Respond, and Recover functions, widely adopted for healthcare cybersecurity risk management.

  4. What does 'MDS²' refer to in the context of medical device security?

    Answer: Manufacturer Disclosure Statement for Medical Device Security

    MDS² (Manufacturer Disclosure Statement for Medical Device Security) is a standardized form used by device manufacturers to disclose security characteristics and capabilities to healthcare organizations.

  5. Which network architecture approach is recommended to isolate medical devices from general hospital networks?

    Answer: Network segmentation using VLANs or dedicated subnets

    Network segmentation using VLANs or dedicated subnets creates separate network zones, limiting the attack surface and preventing lateral movement if a device is compromised.

  6. What is the purpose of a coordinated vulnerability disclosure program in medical device security?

    Answer: To allow researchers to report vulnerabilities so manufacturers can develop patches before public disclosure

    Coordinated vulnerability disclosure allows security researchers to report vulnerabilities to manufacturers who can then develop and release patches before public disclosure, reducing patient risk.

  7. Which U.S. regulatory body has authority over medical device cybersecurity in both premarket and post-market phases?

    Answer: Food and Drug Administration (FDA)

    The FDA has regulatory authority over medical device cybersecurity, issuing guidance for premarket submissions and post-market surveillance requirements for connected medical devices.