Bottom line: Health-ISAC's Medical Device Security Council has established a baseline for MedTech cybersecurity, guiding medical device procurement and deployment.
What's happening: The Baseline was developed in collaboration with medical device manufacturers and security experts, including Dr. Robert Strassler, a renowned cybersecurity expert. The Baseline covers nine domains, including Medical Device Management and Cybersecurity Risk Management. The document outlines best practices for device security, including Secure Configuration and Patch Management.
What to do: Security leaders should review the Baseline and ensure that their medical device vendors are following these guidelines, as well as conducting regular security assessments and implementing robust security controls.