Medical Device Cybersecurity and Information Security Flashcards
7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Medical Device Cybersecurity and Information Security flashcards as text
What is the primary cybersecurity concern when medical devices run legacy operating systems such as Windows XP?
Answer: Lack of manufacturer support and availability of security patches
Legacy operating systems no longer receive security patches from vendors, leaving known vulnerabilities permanently unaddressed and exposing devices to exploitation.
Which IEC standard specifically addresses risk management for IT networks that incorporate medical devices?
Answer: IEC 80001-1 (Risk management of IT networks incorporating medical devices)
IEC 80001-1 specifically addresses risk management for IT networks incorporating medical devices, guiding healthcare organizations in managing risks from networked clinical technology.
What does the security principle of 'defense in depth' mean in the context of medical device cybersecurity?
Answer: Implementing multiple overlapping layers of security controls to protect medical devices
Defense in depth employs multiple overlapping security layers so that if one control fails, additional controls remain to protect the system from compromise.
What is a 'zero-day vulnerability' in the context of medical device security?
Answer: A security flaw unknown to the vendor with no available patch
A zero-day vulnerability is a security flaw unknown to the device vendor, meaning no patch exists at the time of discovery, making it particularly dangerous for patient safety.
Which organization maintains the Common Vulnerability Scoring System (CVSS) used to rate cybersecurity vulnerability severity?
Answer: FIRST (Forum of Incident Response and Security Teams)
CVSS is maintained by FIRST (Forum of Incident Response and Security Teams), providing a standardized, vendor-neutral method for rating the severity of cybersecurity vulnerabilities.
What is the recommended initial action when a critical cybersecurity vulnerability is discovered in an active clinical medical device?
Answer: Follow the facility's incident response plan and notify the manufacturer and FDA as appropriate
Incident response plans provide structured guidance for addressing cybersecurity vulnerabilities while maintaining patient care continuity, including mandatory notifications to manufacturers and regulatory bodies.
What type of cyberattack involves intercepting and potentially altering communications between a medical device and its connected network?
Answer: Man-in-the-Middle (MitM) attack on device communications
A Man-in-the-Middle attack positions an attacker between communicating parties (e.g., a medical device and server), enabling eavesdropping or manipulation of data in transit.