Critical InfrastructureGuideline

SMDDS

OWASP Secure Medical Devices Deployment Standard

The OWASP Secure Medical Devices Deployment Standard provides guidance for the secure deployment of medical devices within healthcare environments, addressing the rising threats such as botnets and malware targeting IoT devices. It emphasizes security measures across device purchasing, network security, interface controls, and incident handling.

Overview

This standard highlights the critical importance of incorporating security measures in the deployment of medical devices, which have traditionally focused solely on patient safety while often neglecting cybersecurity risks. Given the growing risk posed by botnets, malware, and other threats to IoT devices, the standard prescribes actionable controls across areas like procurement processes, perimeter and network security, device-specific measures, and interface and central station configurations. It also advises regular security testing and robust incident response mechanisms to maintain operational integrity in healthcare facilities.

Related in Critical Infrastructure

Critical InfrastructureLaw

Independent Contractors Act 2006

The Independent Contractors Act 2006 is Australian legislation that regulates independent contracting arrangements, protects the rights of independent contractors, and provides mechanisms for addressing unfair services contracts.

Australian Government β€’ Australia β€’ vCompilation No. 7, 1 July 2016

View details
Critical InfrastructureLaw

FBTAA 1986 β€” Fringe Benefits Tax Assessment Act 1986

The Fringe Benefits Tax Assessment Act 1986 is the Australian legislation that governs the taxation of non-cash benefits provided by employers to employees, establishing the rules for identifying, valuing, and taxing fringe benefits.

Australian Government β€’ Australia β€’ vCompilation No. 84, 1 April 2019

View details
Critical InfrastructureLaw

Agricultural and Veterinary Chemicals Code Act 1994

This Australian law establishes the framework for regulating agricultural and veterinary chemical products. It governs approvals, registrations, manufacturing, use, labeling, distribution, and enforcement actions to ensure safety, efficacy, and compliance across the chemicals sector.

Australian Government β€’ Australia β€’ vCompilation No. 29, 21 October 2016

View details
Critical InfrastructureRegulation

EASA Part-IS β€” European Union Aviation Safety Agency (EASA) - Part IS - Easy Access Rules for Information Security

The EASA Part-IS Regulation mandates information security measures within the aviation sector to address digital threats that impact safety. It provides a framework for managing risks, responding to incidents, and safeguarding aviation systems.

European Union β€’ EU β€’ vDecember 2025

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks β€” automatically.

Book your strategy call