ACKNOWLEDGEMENTS
Project Report. This conference paper has been
adapted from part of a NEMECYS project deliverable
report: D2.1 Risk Benefit Schemes (initial) (found at:
https://ec.europa.eu/research/participants/documents
/downloadPublic?documentIds=080166e50edeaf43
&appId=PPGMS).
Funding Statement. This work has been conducted
as part of the NEMECYS project, which is co-funded
by the European Union (101094323), by UK
Research and Innovation (10065802, 10050933 and
10061304), and by the Swiss State Secretariat for
Education, Research and Innovation.
We would like to give thanks to our project partners
for their involvement in risk modelling related use
case discussions. Please note that all views expressed
in this paper are those of the authors, and do not
necessarily represent those above.
REFERENCES
Balogh, E. P., Miller, B. T., Ball, J. R., Committee on
Diagnostic Error in Health Care, Board on Health Care
Services, Institute of Medicine, & The National
Academies of Sciences, Engineering, and Medicine
(Eds.). (2015). Improving Diagnosis in Health Care.
National Academies Press (US).
Biasin E, Kamenjasevic E. Cybersecurity of Medical
Devices: Regulatory Challenges in the European
Union. In: Cohen IG, Minssen T, Price II WN,
Robertson C, Shachar C, eds. The Future of Medical
Device Regulation: Innovation and Protection.
Cambridge University Press; 2022:51-62.
https://doi.org/10.1017/9781108975452.005.
International Organisation for Standardization (ISO). (n.d.).
An easy guide to understanding healthcare data analytics.
https://www.iso.org/healthcare/data-analytics
International Organisation for Standardization (ISO).
(2018). Information technology – Security techniques –
Information security risk management systems –
Overview and vocabulary (ISO Standard No.
27000:2018).
International Organisation for Standardization (ISO).
(2019). Medical devices — Application of risk
management to medical devices (ISO Standard No.
14971:2019).
International Organisation for Standardization (ISO).
(2020). Medical devices — Guidance on the application
of ISO 14971 (ISO Standard No. TR 24971:2020).
International Organisation for Standardization (ISO).
(2022). Information security, cybersecurity and privacy
protection – Guidance on managing information
security risks (ISO Standard No. 27005:2022).
Medical Device Coordination Group (MDCG) (2019).
MDCG 2019-16 Guidance on Cybersecurity for
medical devices. https://ec.europa.eu/docsroom/docu
ments/41863
Medical Device Coordination Group (MDCG) (2023).
MDCG 2023-3. Questions and Answers on vigilance
terms and concepts as outlined in the Regulation (EU)
2017/745 on medical devices. https://health.ec.euro
pa.eu/system/files/2023-02/mdcg_2023-3_en_0.pdf
Mukoro, F. (2011). Care Planning — Mini Topic Review.
NHS Kidney Care. https://www.england.nhs.uk/impro
vement-hub/wp-content/uploads/sites/44/2017/11/Car
e-Planning-Mini-Topic-Review.pdf
NEMECYS. (2023). NEMECYS Use Cases.
https://nemecys.eu/about-us/use-cases
Phillips, S. C., Taylor, S., Boniface, M., Modafferi, S.,
Surridge, M. (2024). Automated Knowledge-Based
Cybersecurity Risk Assessment of Cyber-Physical
Systems. IEEE Access, 12, 82482-82505. doi:
10.1109/ACCESS.2024.3404264
National Health Service [NHS] England. (2023). Medical
devices and digital tools. Version 1.2, 25 May 2023.
https://www.england.nhs.uk/long-read/medical-
devices-and-digital-tools/.
Piggin, R. (2017). Cybersecurity of connected medical
devices. BSI White Paper. Available at: https://www.
bsigroup.com/meddev/LocalFiles/en-US/Whitepapers/
bsi-md-whitepaper-cybersecurity.pdf (Accessed 18
October 2024).
Regulation 2017/745. Regulation (EU) 2017/745 of the
European Parliament and of the Council of 5 April
2017 on medical devices, amending Directive
2001/83/EC, Regulation (EC) No 178/2002 and
Regulation (EC) No 1223/2009 and repealing Council
Directives 90/385/EEC and 93/42/EEC (Text with EEA
relevance.). http://data.europa.eu/eli/reg/2017/745/oj
Regulation 2017/746. Regulation (EU) 2017/746 of the
European Parliament and of the Council of 5 April
2017 on in vitro diagnostic medical devices and
repealing Directive 98/79/EC and Commission
Decision 2010/227/EU (Text with EEA relevance.).
http://data.europa.eu/eli/reg/2017/746/oj
Spyderisk. (2024). Spyderisk Open Project.
https://github.com/Spyderisk
Taylor, S.; Jaatun, M.; Mc Gibney, A.; Seidl, R.;
Hrynchenko, P.; Prosvirin, D. and Mancilla, R. (2024).
A Framework Addressing Challenges in Cybersecurity
Testing of IoT Ecosystems and Components. In
Proceedings of the 9th International Conference on
Internet of Things, Big Data and Security, ISBN 978-
989-758-699-6, ISSN 2184-4976, pages 226-234.
Van Landuyt, D., Joosen, W. (2022). A descriptive study of
assumptions in STRIDE security threat modeling.
Softw Syst Model 21, 2311–2328