{"id":74594,"date":"2024-01-09T03:00:59","date_gmt":"2024-01-09T11:00:59","guid":{"rendered":"https:\/\/www.jamasoftware.com\/?p=74594"},"modified":"2024-01-17T17:10:17","modified_gmt":"2024-01-18T01:10:17","slug":"what-you-need-to-know-ansi-aami-sw962023-medical-device-security","status":"publish","type":"post","link":"https:\/\/www.jamasoftware.com\/legacy\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/","title":{"rendered":"What You Need to Know: ANSI\/AAMI SW96:2023 \u2014 Medical Device Security"},"content":{"rendered":"<div id=\"attachment_74596\" style=\"width: 996px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" aria-describedby=\"caption-attachment-74596\" class=\"wp-image-74596 size-full\" src=\"https:\/\/www.jamasoftware.com\/media\/2024\/01\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg\" alt=\"\" width=\"986\" height=\"512\" srcset=\"https:\/\/www.jamasoftware.com\/legacy\/media\/2024\/01\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg 986w, https:\/\/www.jamasoftware.com\/legacy\/media\/2024\/01\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1-300x156.jpeg 300w\" sizes=\"(max-width: 986px) 100vw, 986px\" \/><p id=\"caption-attachment-74596\" class=\"wp-caption-text\">In this blog, we&#8217;ll recap our eBook, &#8220;What You Need to Know: ANSI\/AAMI SW96:2023 \u2014 Medical Device Security&#8221; &#8211; Click <a href=\"https:\/\/www.jamasoftware.com\/ebook\/what-you-need-to-know-ansi-aami-sw96-2023-medical-device-security\" target=\"_blank\" rel=\"noopener\">HERE<\/a> to download it in its entirety.<\/p><\/div>\n<hr \/>\n<h2>What You Need to Know: ANSI\/AAMI SW96:2023 \u2014 Medical Device Security<\/h2>\n<h3>A comprehensive guide to understanding ANSI\/AAMI SW96:2023 and mitigating security risks<\/h3>\n<p><strong>Introduction<\/strong><\/p>\n<p>Managing risk around a medical device\u2019s entire lifecycle has become increasingly complex. Many devices use third-party components, which is especially true for devices that require a network to operate. This increased need for connectivity, along with other emerging threats, is putting security at the forefront of medical device industry standards.<\/p>\n<p>A recent report titled \u201c<a href=\"https:\/\/healthitsecurity.com\/news\/researchers-observe-59-spike-in-medical-device-security-vulnerabilities#:~:text=Researchers%20found%20993%20vulnerabilities%20within,by%20advanced%20persistent%20threat%20groups\" target=\"_blank\" rel=\"noopener\">2023 State of Cybersecurity for Medical Devices and Healthcare Systems<\/a>\u201d found 993 vulnerabilities in the 966 medical products it examined\u2014a 59% year-over year increase from 2022. Software applications, including those that medical devices relied on to work, accounted for 64% of the vulnerabilities found.<\/p>\n<p>With device vulnerability increasing, new standards aim to keep up with emerging threats. As a result, ANSI\/AAMI SW96:2023 was created to help protect against threats, understand risk, and guide manufacturers in taking the most appropriate actions to enhance security. However, because the standard is relatively new, many device manufacturers are still finalizing the interpretation on how this impacts their organizational processes. If you\u2019re still working to get familiar with the standard, we\u2019ve created a complete guide to make the task easier.<\/p>\n<blockquote><p>Third-party components may increase security risk, with one study finding that software alone accounted for <a href=\"https:\/\/healthitsecurity.com\/news\/researchers-observe-59-spike-in-medical-device-security-vulnerabilities#:~:text=Researchers%20found%20993%20vulnerabilities%20within,by%20advanced%20persistent%20threat%20groups\" target=\"_blank\" rel=\"noopener\">64% of noted vulnerabilities<\/a>.<\/p><\/blockquote>\n<h3>What is ANSI\/AAMI SW96:2023?<\/h3>\n<p>ANSI\/AAMI SW96:2023 guides security risk management for medical devices, aligning with the processes included in ISO 14971:2019.<\/p>\n<p>The new standard addresses the entire lifecycle of a medical device, including areas such as design, production, and post-production. It\u2019s intended for use with <em>AAMI TIR57 Principles for Medical Device Security \u2013 Risk Management<\/em>, which addresses cybersecurity analysis, and AAMI TIR97, Principles for Medical Device Security, <em>which guides processes for managing<\/em> medical devices in the post-market space.<\/p>\n<p>The goal of the new standard is to support manufacturers in ensuring that medical devices are reliable, work as intended, and don\u2019t cause harm to patients, operators, or the environment. It also focuses on mitigating any potential risks around device failure.<\/p>\n<blockquote><p><strong>What is ANSI\/AAMI<\/strong><br \/>\nSW96:2023? The standard includes policies, procedures, and best practices designed to evaluate, control, and monitor potential risks involved with a medical device.<\/p><\/blockquote>\n<hr \/>\n<h4><span style=\"color: #ff6600;\"><strong>RELATED: <\/strong><span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"\/whitepaper\/understanding-integrated-risk-management-for-medical-devices\" target=\"_blank\" rel=\"\u201cnoopener noopener\">Understanding Integrated Risk Management for Medical Device<\/a><\/span><\/span><\/h4>\n<hr \/>\n<h3>Why is security for medical devices important?<\/h3>\n<p>Security has always been important to medical device manufacturers, which is why considerations are included in ISO 14971:2019. However, ANSI\/AAMI SW96:2023 aims to deepen security-related standards.<\/p>\n<p>Addressing potential security risks throughout the entire product lifecycle, including design, production, and post-production, enables manufacturers to identify and mitigate potential risks through a more focused and proactive approach. It helps manufacturers continually identify, review, and safeguard against fast-evolving threats.<\/p>\n<h3>Understanding the security risk management process<\/h3>\n<p>As you get up to speed with ANSI\/AAMI SW96:2023, the \u201csecurity risk management process\u201d section includes details for mitigating potential threats. It includes six major sections, everything from<br \/>\nsecurity risk analysis to production and post-production activities. Each section contains a detailed framework, but for the sake of simplicity, we\u2019ve highlighted a few main points for each.<\/p>\n<h3>The 6 Sections of Security Risk Management<\/h3>\n<ol>\n<li><strong>Security risk analysis.<\/strong> It focuses on selecting product security standards, performing threat modeling, and establishing capabilities to identify and detect security vulnerabilities across a medical device\u2019s entire lifecycle.<\/li>\n<li><strong>Security risk evaluation.<\/strong> Establishes a security assessment strategy and testing processes.<\/li>\n<li><strong>Security risk control.<\/strong> Identifies, designs, and implements security risk control measures, as well as verifying the implementation effectiveness of any security risk control measures.<\/li>\n<li><strong>Evaluation of overall security residual risk acceptability.<\/strong> Determine if the \u201csecurity residual risk\u201d of a device is acceptable.<\/li>\n<li><strong>Security risk management review.<\/strong> A security management report is prepared.<\/li>\n<li><strong>Production and post-production activities.<\/strong> Potential vulnerabilities are monitored to identify any new security risks. Also, it establishes processes to stay aware of new threats, creating security incident response plans and other measures to identify ongoing vulnerabilities.<\/li>\n<\/ol>\n<h4>Section 1: Security Risk Analysis<\/h4>\n<p>The security risk analysis focuses on selecting product security standards, performing threat modeling, and establishing capabilities to identify and detect security vulnerabilities across a medical device\u2019s entire lifecycle. It covers:<\/p>\n<ol>\n<li><strong>Security risk analysis process:<\/strong> It suggests that manufacturers perform a security risk analysis, and the results are recorded in the \u201csecurity risk management file.\u201d<\/li>\n<li><strong>Intended use and reasonably foreseeable misuse:<\/strong> The \u201csecurity risk management\u201d file includes reference documents developed in compliance with clause 5.2 of ISO 14971. It needs to account for \u201cthe use of a medical device in a way not intended by the manufacturer, but which can result from readily predictable behavior.\u201d<\/li>\n<li><strong>Identification of assets and characteristics related to security:<\/strong> You\u2019ll also identify potential medical device vulnerabilities such as third-party components, hardware, and software.<\/li>\n<li><strong>Security risk estimation:<\/strong> You will estimate the associated \u201crisks\u201d for each of the identified security vulnerabilities and potential impacts on areas like confidentiality and integrity.<\/li>\n<\/ol>\n<h4>Section 2: Security Risk Evaluation<\/h4>\n<p>The security risk evaluation establishes a security assessment strategy and testing processes. A few areas it considers:<\/p>\n<ol>\n<li><strong>Evaluation of each security risk:<\/strong> Identify each security risk area, determining if a \u201csecurity reduction\u201d is required.<\/li>\n<li><strong>Evaluation of security risks with a potential safety impact:<\/strong> Consider every potential risk to determine any potential safety impacts.<\/li>\n<\/ol>\n<hr \/>\n<h4><span style=\"color: #ff6600;\"><strong>RELATED: <\/strong><span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"\/whitepaper\/application-of-risk-analysis-techniques-in-jama-to-satisfy-iso-14971\" target=\"_blank\" rel=\"\u201cnoopener noopener\">Application of Risk Analysis Techniques in Jama Connect\u00ae to Satisfy ISO 14971<\/a><\/span><\/span><\/h4>\n<hr \/>\n<h4>Section 3: Security Risk Control<\/h4>\n<p>This section is focused on identifying, designing, and implementing security risk control measures, as well as verifying the implementation effectiveness of any security risk control measures, including:<\/p>\n<ol>\n<li><strong>Security risk control option analysis:<\/strong> Determine if a security risk control measure is appropriate for mitigating security risks to an \u201cacceptable level.\u201d<\/li>\n<li><strong>Implementation of security risk control measures:<\/strong> Security risk measures are selected based on the prior step.<\/li>\n<li><strong>Security residual risk evaluation:<\/strong> After the security risk control measures are implemented, the manufacturer evaluates the security residential risk and records this evaluation in the security risk management file.<\/li>\n<li><strong>Benefit-risk analysis:<\/strong> If a security residual risk is found to be \u201cacceptable\u201d using the criteria created in the security risk management plan, and further security risk control isn\u2019t practical, the manufacturer conducts benefits versus security risk analysis.<\/li>\n<li><strong>Risks arising from security risk control measures:<\/strong> The manufacturer reviews the effects of the security risk control measures to understand whether new security vulnerabilities and threats are introduced that could impact security, safety, or privacy.<\/li>\n<li><strong>Completeness of security risk controls:<\/strong> The manufacturer periodically reviews security risk control activities to ensure all vulnerabilities and threats are considered and security risk control activities are complete.<\/li>\n<\/ol>\n<h4>Section 4: Evaluation of Overall Security Residual Risk Acceptability<\/h4>\n<p>After the security risk controls are implemented and verified, the manufacturer determines if the overall \u201csecurity residual risk\u201d created by the medical device is acceptable.<\/p>\n<h4>Section 5: Security Risk Management Review<\/h4>\n<p>The standard recommends a review of the execution of the security management plan before releasing a new device. According to ANSI\/AAMI SW96:2023, the review should ensure:<\/p>\n<ol>\n<li>The security risk management plan has been appropriately implemented.<\/li>\n<li>The \u201csecurity residual risk\u201d is at an acceptable level.<\/li>\n<li>Methods are in place to gather and review details in the production and post-production phases, and leadership has reviewed and approved the plan.<\/li>\n<\/ol>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-74601\" src=\"https:\/\/www.jamasoftware.com\/media\/2024\/01\/Risk-Flow-Chart.png\" alt=\"Image showing the flow of different stages of risk.\" width=\"423\" height=\"600\" srcset=\"https:\/\/www.jamasoftware.com\/legacy\/media\/2024\/01\/Risk-Flow-Chart.png 423w, https:\/\/www.jamasoftware.com\/legacy\/media\/2024\/01\/Risk-Flow-Chart-212x300.png 212w\" sizes=\"(max-width: 423px) 100vw, 423px\" \/><\/p>\n<h4>Section 6: Production and Post-production Activities<\/h4>\n<p>The final section is focused on establishing, documenting, and maintaining a system to monitor, assemble, and review information about medical device security in the production and post-market phases. Also, it establishes processes to stay aware of new threats, creating security incident response plans and other measures to identify ongoing vulnerabilities.<\/p>\n<hr \/>\n<h4 style=\"text-align: center;\"><span style=\"color: #ff6600;\"><strong>DOWNLOAD THE ENTIRE EBOOK: <\/strong><span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"\/ebook\/what-you-need-to-know-ansi-aami-sw96-2023-medical-device-security\" target=\"_blank\" rel=\"\u201cnoopener noopener\">What You Need to Know: ANSI\/AAMI SW96:2023 \u2014 Medical Device Security<\/a><\/span><\/span><\/h4>\n<hr \/>\n<p><a href=\"https:\/\/www.jamasoftware.com\/platform\/jama-connect\/trial\/\"><img decoding=\"async\" class=\"aligncenter wp-image-58664\" src=\"https:\/\/www.jamasoftware.com\/media\/2021\/12\/Trial-Banner.png\" alt=\"\" width=\"302\" height=\"51\" srcset=\"https:\/\/www.jamasoftware.com\/legacy\/media\/2021\/12\/Trial-Banner.png 894w, https:\/\/www.jamasoftware.com\/legacy\/media\/2021\/12\/Trial-Banner-300x51.png 300w\" sizes=\"(max-width: 302px) 100vw, 302px\" \/><\/a><\/p>\n<input class=\"fooboxshare_post_id\" type=\"hidden\" value=\"74594\"\/>","protected":false},"excerpt":{"rendered":"<p>What You Need to Know: ANSI\/AAMI SW96:2023 \u2014 Medical Device Security A comprehensive guide to understanding ANSI\/AAMI SW96:2023 and mitigating security risks Introduction Managing risk around a medical device\u2019s entire lifecycle has become increasingly complex. Many devices use third-party components, which is especially true for devices that require a network to operate. This increased need [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":74596,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[854],"tags":[841,840,121],"industry":[574],"class_list":["post-74594","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-compliance-regulation","tag-product-development-management","tag-risk-management","industry-medical-devices"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.1 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>ANSI\/AAMI SW96:2023 - Medical Device Security - Jama Software<\/title>\n<meta name=\"description\" content=\"In this blog, we overview our comprehensive guide to understanding ANSI\/AAMI SW96:2023 and mitigating security risks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What You Need to Know: ANSI\/AAMI SW96:2023 \u2014 Medical Device Security\" \/>\n<meta property=\"og:description\" content=\"In this blog, we overview our comprehensive guide to understanding ANSI\/AAMI SW96:2023 and mitigating security risks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Jama Software\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-09T11:00:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-18T01:10:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.jamasoftware.com\/legacy\/media\/2024\/01\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"986\" \/>\n\t<meta property=\"og:image:height\" content=\"512\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jama Software\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jama Software\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/\"},\"author\":{\"name\":\"Jama Software\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/#\\\/schema\\\/person\\\/59a942565a528aa5f56b240c9342fc7f\"},\"headline\":\"What You Need to Know: ANSI\\\/AAMI SW96:2023 \u2014 Medical Device Security\",\"datePublished\":\"2024-01-09T11:00:59+00:00\",\"dateModified\":\"2024-01-18T01:10:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/\"},\"wordCount\":1291,\"image\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.jamasoftware.com\\\/media\\\/2024\\\/01\\\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg\",\"keywords\":[\"Compliance &amp; Regulation\",\"Product Development &amp; Management\",\"risk management\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/\",\"url\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/\",\"name\":\"ANSI\\\/AAMI SW96:2023 - Medical Device Security - Jama Software\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.jamasoftware.com\\\/media\\\/2024\\\/01\\\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg\",\"datePublished\":\"2024-01-09T11:00:59+00:00\",\"dateModified\":\"2024-01-18T01:10:17+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/#\\\/schema\\\/person\\\/59a942565a528aa5f56b240c9342fc7f\"},\"description\":\"In this blog, we overview our comprehensive guide to understanding ANSI\\\/AAMI SW96:2023 and mitigating security risks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.jamasoftware.com\\\/media\\\/2024\\\/01\\\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg\",\"contentUrl\":\"https:\\\/\\\/www.jamasoftware.com\\\/media\\\/2024\\\/01\\\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg\",\"width\":986,\"height\":512},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.jamasoftware.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What You Need to Know: ANSI\\\/AAMI SW96:2023 \u2014 Medical Device Security\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/#website\",\"url\":\"https:\\\/\\\/www.jamasoftware.com\\\/\",\"name\":\"Jama Software\",\"description\":\"Jama Connect\u00ae #1 in Requirements Management\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.jamasoftware.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/#\\\/schema\\\/person\\\/59a942565a528aa5f56b240c9342fc7f\",\"name\":\"Jama Software\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6e1172c5d380b2a20a9e5b5a4c0fb4e38bc497dc27ce100567da29abe37001af?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6e1172c5d380b2a20a9e5b5a4c0fb4e38bc497dc27ce100567da29abe37001af?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6e1172c5d380b2a20a9e5b5a4c0fb4e38bc497dc27ce100567da29abe37001af?s=96&d=mm&r=g\",\"caption\":\"Jama Software\"},\"description\":\"Subject matter experts from Jama Software provide guidance and best practices on requirements management, test management, compliance and regulation, risk management, and complex product and software development.\",\"url\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/author\\\/jama-software\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"ANSI\/AAMI SW96:2023 - Medical Device Security - Jama Software","description":"In this blog, we overview our comprehensive guide to understanding ANSI\/AAMI SW96:2023 and mitigating security risks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/","og_locale":"en_US","og_type":"article","og_title":"What You Need to Know: ANSI\/AAMI SW96:2023 \u2014 Medical Device Security","og_description":"In this blog, we overview our comprehensive guide to understanding ANSI\/AAMI SW96:2023 and mitigating security risks.","og_url":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/","og_site_name":"Jama Software","article_published_time":"2024-01-09T11:00:59+00:00","article_modified_time":"2024-01-18T01:10:17+00:00","og_image":[{"width":986,"height":512,"url":"https:\/\/www.jamasoftware.com\/legacy\/media\/2024\/01\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg","type":"image\/jpeg"}],"author":"Jama Software","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jama Software","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/#article","isPartOf":{"@id":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/"},"author":{"name":"Jama Software","@id":"https:\/\/www.jamasoftware.com\/#\/schema\/person\/59a942565a528aa5f56b240c9342fc7f"},"headline":"What You Need to Know: ANSI\/AAMI SW96:2023 \u2014 Medical Device Security","datePublished":"2024-01-09T11:00:59+00:00","dateModified":"2024-01-18T01:10:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/"},"wordCount":1291,"image":{"@id":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.jamasoftware.com\/media\/2024\/01\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg","keywords":["Compliance &amp; Regulation","Product Development &amp; Management","risk management"],"articleSection":["Cybersecurity"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/","url":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/","name":"ANSI\/AAMI SW96:2023 - Medical Device Security - Jama Software","isPartOf":{"@id":"https:\/\/www.jamasoftware.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/#primaryimage"},"image":{"@id":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.jamasoftware.com\/media\/2024\/01\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg","datePublished":"2024-01-09T11:00:59+00:00","dateModified":"2024-01-18T01:10:17+00:00","author":{"@id":"https:\/\/www.jamasoftware.com\/#\/schema\/person\/59a942565a528aa5f56b240c9342fc7f"},"description":"In this blog, we overview our comprehensive guide to understanding ANSI\/AAMI SW96:2023 and mitigating security risks.","breadcrumb":{"@id":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/#primaryimage","url":"https:\/\/www.jamasoftware.com\/media\/2024\/01\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg","contentUrl":"https:\/\/www.jamasoftware.com\/media\/2024\/01\/2fe8f5c4-37b4-47b3-b012-1ca0b0d208a1.jpeg","width":986,"height":512},{"@type":"BreadcrumbList","@id":"https:\/\/www.jamasoftware.com\/blog\/what-you-need-to-know-ansi-aami-sw962023-medical-device-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.jamasoftware.com\/"},{"@type":"ListItem","position":2,"name":"What You Need to Know: ANSI\/AAMI SW96:2023 \u2014 Medical Device Security"}]},{"@type":"WebSite","@id":"https:\/\/www.jamasoftware.com\/#website","url":"https:\/\/www.jamasoftware.com\/","name":"Jama Software","description":"Jama Connect\u00ae #1 in Requirements Management","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.jamasoftware.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.jamasoftware.com\/#\/schema\/person\/59a942565a528aa5f56b240c9342fc7f","name":"Jama Software","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/6e1172c5d380b2a20a9e5b5a4c0fb4e38bc497dc27ce100567da29abe37001af?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/6e1172c5d380b2a20a9e5b5a4c0fb4e38bc497dc27ce100567da29abe37001af?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6e1172c5d380b2a20a9e5b5a4c0fb4e38bc497dc27ce100567da29abe37001af?s=96&d=mm&r=g","caption":"Jama Software"},"description":"Subject matter experts from Jama Software provide guidance and best practices on requirements management, test management, compliance and regulation, risk management, and complex product and software development.","url":"https:\/\/www.jamasoftware.com\/blog\/author\/jama-software\/"}]}},"_links":{"self":[{"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/posts\/74594","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/comments?post=74594"}],"version-history":[{"count":0,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/posts\/74594\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/media\/74596"}],"wp:attachment":[{"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/media?parent=74594"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/categories?post=74594"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/tags?post=74594"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/industry?post=74594"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}