Threat Assessment and Risk Analysis (TARA) for Interoperable Medical Devices in the Operating Room Inspired by the Automotive Industry

Puder, Andreas ORCID iD icon; Henle, Jacqueline; Sax, Eric 1
1 Institut für Technik der Informationsverarbeitung (ITIV), Karlsruher Institut für Technologie (KIT)


Prevailing trends in the automotive and medical device industry, such as life cycle overarching configurability, connectivity, and automation, require an adaption of development processes, especially regarding the security and safety thereof. The changing requirements imply that interfaces are more exposed to the outside world, making them more vulnerable to cyberattacks or data leaks. Consequently, not only do development processes need to be revised but also cybersecurity countermeasures and a focus on safety, as well as privacy, have become vital. While vehicles are especially exposed to cybersecurity and safety risks, the medical devices industry faces similar issues. In the automotive industry, proposals and draft regulations exist for security-related risk assessment processes. The medical device industry, which has less experience in these topics and is more heterogeneous, may benefit from drawing inspiration from these efforts. We examined and compared current standards, processes, and methods in both the automotive and medical industries. Based on the requirements regarding safety and security for risk analysis in the medical device industry, we propose the adoption of methods already established in the automotive industry. ... mehr

DOI: 10.5445/IR/1000157846
Veröffentlicht am 18.04.2023
DOI: 10.3390/healthcare11060872
Zitationen: 3
Zugehörige Institution(en) am KIT Institut für Technik der Informationsverarbeitung (ITIV)
Publikationstyp Zeitschriftenaufsatz
Publikationsjahr 2023
Sprache Englisch
Identifikator ISSN: 2227-9032
KITopen-ID: 1000157846
Erschienen in Healthcare (Switzerland)
Verlag MDPI
Band 11
Heft 6
Seiten Art.-Nr.: 872
Bemerkung zur Veröffentlichung Gefördert durch den KIT-Publikationsfonds
Vorab online veröffentlicht am 16.03.2023
Schlagwörter safety; security, medical devices, automotive, Failure-Mode and Effect Analysis (FMEA), Threat Assessment and Risk Analysis (TARA), processes
Nachgewiesen in Web of Science
