| Part B: Supplementary Information Sheet (SIS) |
|
FR Recognition List Number
|
043
|
Date of Entry 06/27/2016
|
|
FR Recognition Number
|
13-83
|
| Standard | |
AAMI TIR57:2016 Principles for medical device security - Risk management. |
|
Scope/Abstract| Provides guidance on methods to perform information security risk management for a medical device in the context of the Safety Risk Management process required by ISO 14971. The TIR incorporates the expanded view of risk management from IEC 80001-1 by incorporating the same key properties of Safety, Effectiveness and Data & Systems Security with Annexes that provide process details and illustrative examples. |
|
| Extent of Recognition
|
Rationale for Recognition
This standard is relevant to medical devices and is recognized on its scientific and technical merit and/or because it supports existing regulatory policies.
NOTE: Conformance to this standard may not satisfy all the cybersecurity requirements outlined in Section 524B of FD&C Act or the recommendations in the (1) listed below (Relevant FDA Guidance). Manufacturers should consider the information contained within these resources in their assessment of cybersecurity for their device. |
|
Relevant FDA Guidance and/or Supportive Publications*
1. Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, Guidance for Industry and Food and Drug Administration Staff, issued February 2026.
2. Postmarket Management of Cybersecurity in Medical Devices, Guidance for Industry and Food and Drug Administration Staff, issued December 2016.
3. Content of Premarket Submissions for Device Software Functions, Guidance for Industry and Food and Drug Administration Staff, issued June 2023.
4. NIST Special Publication 800-82, Guide to Industrial Control Systems (ICS) Security, June 2011.
Appropriate Use of Voluntary Consensus Standards in Premarket Submissions for Medical Devices - Guidance for Industry and Food and Drug Administration Staff, issued September 2018.
Appropriate Use of Voluntary Consensus Standards in Premarket Submissions for Medical Devices - Guidance for Industry and Food and Drug Administration Staff, issued September 2018. |
|
| FDA Technical Contact
|
| Standards Development Organization
|
| FDA Specialty Task Group (STG)
|
| *These are provided as examples and others may be applicable. |