
ACKNOWLEDGEMENTS
This work has been conducted as part of the NEME-
CYS project, which is co-funded by the European
Union (101094323), by UK Research and Innova-
tion (10065802, 10050933 and 10061304), and by the
Swiss State Secretariat for Education, Research and
Innovation.
Please note that this conference paper adapts and
extends part of a NEMECYS project deliverable re-
port: D2.1 Risk Benefit Schemes (initial).
REFERENCES
Andress, J. (2014). The basics of information security: un-
derstanding the fundamentals of InfoSec in theory and
practice. Syngress.
Badrouchi, F., Aymond, A., Haerinia, M., Badrouchi, S.,
Selvaraj, D. F., Tavakolian, K., Ranganathan, P., and
Eswaran, S. (2020). Cybersecurity Vulnerabilities in
Biomedical Devices: A Hierarchical Layered Frame-
work, pages 157–184. Springer International Publish-
ing, Cham.
Busnatu, S. S., Niculescu, A.-G., Bolocan, A., An-
dronic, O., Pantea Stoian, A. M., Scafa-Udris
,
te, A.,
St
˘
anescu, A. M. A., P
˘
aduraru, D. N., Nicolescu, M. I.,
Grumezescu, A. M., and Jinga, V. (2022). A review of
digital health and biotelemetry: Modern approaches
towards personalized medicine and remote health as-
sessment. Journal of Personalized Medicine, 12(10).
EU (2017a). Regulation (EU) 2017/745 of the Euro-
pean Parliament and of the Council of 5 April 2017
on medical devices, amending Directive 2001/83/EC,
Regulation (EC) No 178/2002 and Regulation (EC)
No 1223/2009 and repealing Council Directives
90/385/EEC and 93/42/EEC (Text with EEA rel-
evance.). http://data.europa.eu/eli/reg/2017/745/oj.
Accessed: 2024-11-13.
EU (2017b). Regulation (EU) 2017/746 of the Euro-
pean Parliament and of the Council of 5 April 2017
on in vitro diagnostic medical devices and repeal-
ing Directive 98/79/EC and Commission Decision
2010/227/EU (Text with EEA relevance.). https:
//eur-lex.europa.eu/eli/reg/2017/746/oj. Accessed:
2024-11-13.
European Commission (2016). MEDDEV (MEDical
DEVices Documents) 2.7/1 revision 4 - Clini-
cal evaluation: a guide for manufacturers and
notified bodies under directives 93/42/EEC and
90/385/EEC. Guidelines on Medical Devices.
https://ec.europa.eu/docsroom/documents/17522/
attachments/1/translations/. Accessed: 2024-11-08.
Food & Drug Administration (FDA) (2019). Im-
plants and Prosthetics. https://www.fda.gov/
medical-devices/products-and-medical-procedures/
implants-and-prosthetics. Accessed: 2024-11-18.
IEC (2023). International Electrotechnical Commission,
IEC GUIDE 120:2023 - Security aspects - Guidelines
for their inclusion in publications.
International Medical Device Regulators Forum
(IMDRF) (2024). Adverse Event Terminol-
ogy. https://www.imdrf.org/working-groups/
adverse-event-terminology. Accessed: 2024-11-
20.
ISO (2019). International organization for standardization,
ISO 14971:2019 - medical devices — application of
risk management to medical devices.
ISO/IEC (2018). International organization for standardiza-
tion, ISO/IEC 27000:2018 - information technology
— security techniques — information security man-
agement systems — overview and vocabulary. https:
//www.iso.org/standard/73906.html.
ISO/IEC (2022). International organization for standard-
ization, ISO/IEC 27005:2022 - information security,
cybersecurity and privacy protection — guidance on
managing information security risks.
ISO/TR (2020). International organization for standardiza-
tion, ISO/TR 24971:2020 - medical devices — guid-
ance on the application of iso 14971.
Les
´
en, E., Bj
¨
orholt, I., Ingelg
˚
ard, A., and Olson, F. J.
(2017). Exploration and preferential ranking of pa-
tient benefits of medical devices: A new and generic
instrument for health economic assessments. Inter-
national Journal of Technology Assessment in Health
Care, 33(4):463–471.
MDCG (2019). MDCG 2019-16 rev.1 - guidance on cyber-
security for medical devices. Accessed: 2024-11-13.
MDCG (2022). MDCG 2022-2 Guidance on general princi-
ples of clinical evidence for In Vitro Diagnostic med-
ical devices (IVDs). Accessed: 2024-11-18.
MDCG (2024). MDCG 2023-3 rev. 1 - questions and an-
swers on vigilance terms and concepts as outlined
in the regulation (eu) 2017/745 and regulation (eu)
2017/746. Accessed: 2024-11-13.
Medicines & Healthcare products Regulatory Agency
(MHRA) (2023). Guidance for manufacturers on
reporting adverse incidents involving Software as a
Medical Device under the vigilance system. Ac-
cessed: 2024-11-18.
MITRE and MDIC (2021). Playbook for
Threat Modeling Medical Devices. https:
//www.mitre.org/sites/default/files/2021-11/
Playbook-for-Threat-Modeling-Medical-Devices.
pdf. Accessed: 2024-11-08.
Neil, L., Haney, J. M., Buchanan, K., and Healy, C. (2023).
Analyzing cybersecurity definitions for non-experts.
In Furnell, S. and Clarke, N., editors, Human Aspects
of Information Security and Assurance, pages 391–
404, Cham. Springer Nature Switzerland.
Parker, D. B. (1998). Fighting computer crime: A new
framework for protecting information. John Wiley &
Sons, Inc.
Phillips, S. C., Taylor, S., Boniface, M., Modafferi, S., and
Surridge, M. (2024). Automated knowledge-based cy-
bersecurity risk assessment of cyber-physical systems.
IEEE Access, 12:82482–82505.
Systematisation of Security Risk Knowledge Across Different Domains: A Case Study of Security Implications of Medical Devices
347