A number of draft standards were released for comment, including including several related to specific security for medical devices and Health IT:
- AAMI TIR38 – AAMI Medical device safety assurance case guidance
- IEC Health SW Standards Framework
- ISO 27799 Health informatics “Information management in health using ISO/IEC 27002”
- IEC TR 80001-2-8, Application of risk management for IT networks incorporating medical devices – Part 2-8: Application guidance – Guidance on standards for establishing the security capabilities identified in IEC 80001-2-2
- NIST Special Publication 800-160 Systems Security Engineering. This guidance infuses systems security engineering techniques, methods, and practices into the systems and software engineering processes defined in ISO/IEC 15288. This NIST document is publicly available at the link provided. NIST SP800-160 Draft