UNE EN IEC 81001-5-1:2022
Health software and health IT systems safety, effectiveness and security - Part 5-1: Security - Activities in the product life cycle (Endorsed by Asociación Española de Normalización in March of 2022.)
Seguridad y eficacia del software sanitario y de los sistemas de tecnología de la información sanitarios. Parte 5-1: Seguridad. Actividades en el ciclo de vida del producto (Ratificada por la Asociación Española de Normalización en marzo de 2022.)
| Standard number: | UNE EN IEC 81001-5-1:2022 |
| Pages: | 65 |
| Released: | 2022-03-01 |
| Status: | Standard |
UNE EN IEC 81001-5-1:2022
This document defines the LIFE CYCLE requirements for development and maintenance of HEALTH SOFTWARE needed to support conformity to IEC 62443-4-1 taking the specific needs for HEALTH SOFTWARE into account. The set of PROCESSES, ACTIVITIES, and TASKS described in this document establishes a common framework for secure HEALTH SOFTWARE LIFE CYCLE PROCESSES. The purpose is to increase the information SECURITY of HEALTH SOFTWARE by establishing certain ACTIVITIES and TASKS in the HEALTH SOFTWARE LIFE CYCLE PROCESSES and also by increasing the SECURITY of SOFTWARE LIFE CYCLE PROCESSES themselves. It is important to maintain an appropriate balance of the key properties SAFETY, effectiveness and SECURITY as discussed in IEC 81001-1. This document excludes specification of ACCOMPANYING DOCUMENTATION contents. This document applies to the development and maintenance of HEALTH SOFTWARE by a MANUFACTURER, but recognizes the critical importance of bi-lateral communication with organizations (e.g. HDOs) who have SECURITY responsibilities for the HEALTH SOFTWARE and the systems it is incorporated into, once the software has been developed and released. The IEC/ISO 81001-5 series of standards (for which this is part 1, is therefore being designed to include future parts addressing SECURITY that apply to the implementation, operations and use phases of the LIFE CYCLE for organizations such as HDOs. Medical device software is a subset of HEALTH SOFTWARE. Therefore, this document applies to: " Software as part of a medical device; " Software as part of hardware specifically intended for health use; " Software as a medical device (SaMD); and " Software-only PRODUCT for other health use. Note: In this document, the scope of software considered part of the LIFE CYCLE ACTIVITIES for secure HEALTH SOFTWARE is larger and includes more software (drivers, platforms, operating systems) than for SAFETY, because for SECURITY the focus will be on any use including foreseeable unauthorized access rather than just the INTENDED USE.
