CCE Medical Device Cybersecurity and Information Security 2 — Questions and Answers
Question 1: What is the primary cybersecurity concern when medical devices run legacy operating systems such as Windows XP?
- Higher power consumption leading to increased operating costs
- Lack of manufacturer support and availability of security patches (Correct answer)
- Reduced processing speed affecting device performance
- Incompatibility with modern display technology
Correct answer: Lack of manufacturer support and availability of security patches
Legacy operating systems no longer receive security patches from vendors, leaving known vulnerabilities permanently unaddressed and exposing devices to exploitation.
Question 2: Which IEC standard specifically addresses risk management for IT networks that incorporate medical devices?
- IEC 62304 (Medical device software lifecycle)
- IEC 62443 (Industrial automation security)
- IEC 80001-1 (Risk management of IT networks incorporating medical devices) (Correct answer)
- ISO 14971 (Medical device risk management)
Correct answer: IEC 80001-1 (Risk management of IT networks incorporating medical devices)
IEC 80001-1 specifically addresses risk management for IT networks incorporating medical devices, guiding healthcare organizations in managing risks from networked clinical technology.
Question 3: What does the security principle of 'defense in depth' mean in the context of medical device cybersecurity?
- Using a single, highly capable firewall to protect all clinical network devices
- Implementing multiple overlapping layers of security controls to protect medical devices (Correct answer)
- Encrypting only the most sensitive patient data stored on devices
- Restricting all physical access to server rooms containing device data
Correct answer: Implementing multiple overlapping layers of security controls to protect medical devices
Defense in depth employs multiple overlapping security layers so that if one control fails, additional controls remain to protect the system from compromise.
Question 4: What is a 'zero-day vulnerability' in the context of medical device security?
- A vulnerability discovered on the first day of device deployment in a facility
- A security flaw unknown to the vendor with no available patch (Correct answer)
- A device that has never been connected to a network
- A vulnerability that only affects devices older than one year
Correct answer: A security flaw unknown to the vendor with no available patch
A zero-day vulnerability is a security flaw unknown to the device vendor, meaning no patch exists at the time of discovery, making it particularly dangerous for patient safety.
Question 5: Which organization maintains the Common Vulnerability Scoring System (CVSS) used to rate cybersecurity vulnerability severity?
- Food and Drug Administration (FDA)
- FIRST (Forum of Incident Response and Security Teams) (Correct answer)
- National Institute of Standards and Technology (NIST)
- International Electrotechnical Commission (IEC)
Correct answer: FIRST (Forum of Incident Response and Security Teams)
CVSS is maintained by FIRST (Forum of Incident Response and Security Teams), providing a standardized, vendor-neutral method for rating the severity of cybersecurity vulnerabilities.
Question 6: What is the recommended initial action when a critical cybersecurity vulnerability is discovered in an active clinical medical device?
- Immediately disconnect all affected devices from the network regardless of patient impact
- Follow the facility's incident response plan and notify the manufacturer and FDA as appropriate (Correct answer)
- Continue normal operations and wait until the device warranty expires to replace it
- Replace all affected devices immediately without consulting the manufacturer
Correct answer: Follow the facility's incident response plan and notify the manufacturer and FDA as appropriate
Incident response plans provide structured guidance for addressing cybersecurity vulnerabilities while maintaining patient care continuity, including mandatory notifications to manufacturers and regulatory bodies.
Question 7: What type of cyberattack involves intercepting and potentially altering communications between a medical device and its connected network?
- Denial of Service (DoS) attack targeting device availability
- Man-in-the-Middle (MitM) attack on device communications (Correct answer)
- SQL injection attack on the device database
- Phishing attack targeting clinical staff credentials
Correct answer: Man-in-the-Middle (MitM) attack on device communications
A Man-in-the-Middle attack positions an attacker between communicating parties (e.g., a medical device and server), enabling eavesdropping or manipulation of data in transit.
What is the primary cybersecurity concern when medical devices run legacy operating systems such as Windows XP?