Stay secure with CISA’s guidance on design and product safety

August 11, 2024
1 min read




Article Summary

TLDR:

Key points:

  • Cybersecurity and Infrastructure Security Agency and FBI released guidance on secure software products
  • Health care organizations should require secure by design software from developers

Article Summary:

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI recently issued guidance on secure by design software products, emphasizing the importance of assessing product security maturity and ensuring manufacturers follow secure by design principles. John Riggi, AHA national advisor for cybersecurity and risk, highlighted the need for consumers, including health care organizations, to drive market forces for better securely designed software. It is recommended that health care organizations demand that software developers meet cybersecurity specifications outlined in the guide during the procurement phase. Riggi also emphasized the importance of software developers taking primary responsibility for software security, rather than end users, promoting a secure by design and demand approach.

For more information on cyber and risk issues, individuals can contact Riggi at jriggi@aha.org. Additional cyber and risk resources and threat intelligence are available at aha.org/cybersecurity.


Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and