한국어

Chapter 4: Secure Development Lifecycle

Building Security into Medical Device Design and Development

4.1 Security by Design Principles

Secure medical devices begin with security-focused design. Integrating security into every phase of the development lifecycle is more effective and less costly than attempting to add security after development is complete. This chapter explores the practices and processes that enable manufacturers to build inherently secure medical devices.

The concept of "security by design" means that security is not an afterthought but a fundamental consideration from the earliest stages of product conception through end-of-life. This approach aligns with regulatory expectations and results in devices that are more resilient to evolving threats.

15x
Cost to Fix Post-Release vs. Design
70%
Vulnerabilities from Design Flaws
40%
Reduction via Secure SDL
IEC 62443-4-1
SDL Standard for Medical Devices

4.2 Secure Development Lifecycle Framework

A comprehensive secure development lifecycle (SDL) encompasses security activities across all development phases. This framework ensures that security is systematically addressed from requirements through deployment and maintenance.

SDL Phase Overview

The secure development lifecycle integrates security into each phase: Requirements (security requirements definition), Design (threat modeling and security architecture), Implementation (secure coding), Verification (security testing), Release (security review), and Maintenance (vulnerability management).

SDL Phase Security Activities Key Outputs
Requirements Security requirements, risk criteria, compliance mapping Security requirements specification
Design Threat modeling, security architecture, component selection Threat model, architecture docs, SBOM
Implementation Secure coding, code review, static analysis Secure code, analysis reports
Verification Security testing, penetration testing, fuzz testing Test results, vulnerability findings
Release Final security review, regulatory submission Security attestation, release package
Maintenance Vulnerability monitoring, patching, incident response Security updates, advisories

4.3 Threat Modeling

Threat modeling is a systematic approach to identifying and prioritizing potential security threats to a medical device. It enables designers to understand how attackers might compromise the device and implement appropriate countermeasures.

Threat Modeling Methodologies

Several methodologies can be applied to medical device threat modeling:

Methodology Approach Best Used For
STRIDE Categorizes threats by type (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege) Comprehensive threat identification
DREAD Quantifies risk based on Damage, Reproducibility, Exploitability, Affected users, Discoverability Prioritizing threats by severity
Attack Trees Hierarchical analysis of attack paths Understanding complex attack scenarios
PASTA Process for Attack Simulation and Threat Analysis Business risk-focused analysis

Medical Device Threat Model Components

Key Threat Model Elements

4.4 Security Architecture

Security architecture defines how security controls are implemented within the device design. A well-designed security architecture provides defense in depth and reduces the impact of potential compromises.

Core Security Architecture Principles

Security Control Categories

Control Category Implementation Medical Device Examples
Authentication Verify identity of users and systems Clinician login, device-to-server auth
Authorization Control access to resources and functions Role-based access, privilege levels
Encryption Protect data confidentiality and integrity TLS communications, encrypted storage
Integrity Detect and prevent unauthorized modifications Code signing, secure boot
Auditing Record security-relevant events Access logs, configuration changes

4.5 Secure Coding Practices

Secure coding transforms security requirements and architecture into robust, vulnerability-resistant code. Following secure coding standards reduces the introduction of common vulnerabilities during implementation.

Common Vulnerability Prevention

Vulnerability Class Description Prevention Techniques
Buffer Overflow Writing beyond allocated memory Bounds checking, safe functions, memory-safe languages
Injection Flaws Untrusted data in commands/queries Input validation, parameterized queries
Authentication Bypass Circumventing identity verification Proper session management, multi-factor auth
Hardcoded Credentials Static passwords in code Secure credential storage, key management
Insecure Deserialization Untrusted data reconstruction Input validation, type checking

Coding Standards for Medical Devices

⚠️ Language-Specific Guidelines

Medical devices should follow established secure coding standards appropriate to their implementation language: CERT C/C++, MISRA C, OWASP guidelines for web technologies, and language-specific security guides. Static analysis tools should be configured to enforce these standards.

4.6 Software Bill of Materials (SBOM)

The Software Bill of Materials is a comprehensive inventory of software components within a device. SBOMs enable vulnerability tracking and are now required by FDA regulations.

SBOM Requirements

Element Description Importance
Component Name Identifier for each software component Essential for vulnerability matching
Version Specific version of each component Critical for CVE correlation
Supplier Source of each component Supply chain tracking
Dependency Relationships How components relate to each other Understanding impact scope
Hash/Checksum Cryptographic verification of component Integrity validation

SBOM Formats

4.7 Security Testing

Security testing verifies that security controls are implemented correctly and that the device resists attack. A comprehensive testing strategy combines multiple techniques to achieve thorough coverage.

Testing Techniques

Testing Pyramid for Medical Device Security

Effective security testing combines static analysis (code review without execution), dynamic analysis (testing running code), interactive testing (automated crawling and attack), and manual penetration testing (expert human analysis).

Testing Type Method Coverage
Static Analysis (SAST) Automated code analysis without execution Coding vulnerabilities, quality issues
Dynamic Analysis (DAST) Testing running application Runtime vulnerabilities, configuration issues
Fuzz Testing Random/mutated input testing Input validation, crash bugs
Penetration Testing Simulated attacks by security experts Real-world attack scenarios
Protocol Testing Analysis of communication protocols Protocol implementation vulnerabilities

4.8 Secure Update Mechanisms

Medical devices must be capable of receiving security updates throughout their lifecycle. The update mechanism itself must be secured to prevent attackers from deploying malicious firmware.

Update Mechanism Requirements

✓ Update Best Practices

4.9 Documentation and Traceability

Comprehensive documentation is essential for regulatory compliance and ongoing security management. Traceability ensures that security requirements can be traced through design, implementation, and testing.

Required Documentation

Document Purpose Key Contents
Security Requirements Define security objectives and constraints Functional and non-functional security requirements
Threat Model Document identified threats and mitigations Attack surfaces, threat actors, risk ratings
Security Architecture Describe security control implementation Architecture diagrams, control specifications
Test Reports Evidence of security testing Test cases, results, remediation actions
SBOM Software component inventory Components, versions, suppliers, dependencies

4.10 DevSecOps for Medical Devices

DevSecOps integrates security into continuous integration and delivery pipelines. While medical devices require additional validation steps, DevSecOps practices can improve security while maintaining development velocity.

DevSecOps Integration Points

📌 Key Takeaways

📝 Review Questions

  1. What are the six phases of a secure development lifecycle for medical devices, and what are the key security activities in each phase?
  2. Compare and contrast the STRIDE and DREAD threat modeling methodologies. When would you use each in medical device development?
  3. Describe the core security architecture principles and explain how each applies to medical device design.
  4. What are the five most common vulnerability classes in medical device software, and what coding practices prevent each?
  5. What elements must be included in an SBOM according to FDA requirements, and why is each element important for vulnerability management?
  6. Design a security testing strategy for a network-connected infusion pump. What testing techniques would you use and why?

Korea Industrial, Research, Education Infrastructure Mapping

Korea operates its industrial ecosystem and standardization system through the following core infrastructure. Korea Top 5 Groups: Samsung, Hyundai Motor, LG, SK, Lotte. Each group operates standardization committees and ISO/IEC TC Korean secretariats. Samsung Electronics (semiconductors, displays, home appliances, telecom)·Hyundai Motor (automobiles, mobility)·LG Electronics (home appliances, displays, OLED)·SK hynix (memory)·LG Energy Solution·Samsung SDI (batteries)·POSCO Future M (materials)·Hyundai Mobis (parts). Korean IT Big Tech: NAVER (search, cloud, AI HyperCLOVA)·Kakao (messenger, payment, mobility, banking)·Coupang (e-commerce, logistics)·Karrot Market·Toss·Woowa Brothers. Korea Telcos: SK Telecom·KT·LG U+. 5G·5G dedicated networks·B2B cloud·AI businesses operating. Korea Top 7 Research Universities: Seoul National University·KAIST·POSTECH·Yonsei University·Korea University·UNIST·DGIST·GIST. All serve as standardization R&D bases and ISO/IEC/IEEE Korean chairs. Korea Government-affiliated National Research Institutes (26): KIST, KAERI, KIMM, KIER, KFRI, KRICT, KRIBB, KARI, KASI, KIGAM, KICT, KISTI, KETI, ETRI, NIMS, KIMS, KISDI, KOTRA, STEPI, KOEN, KICCE, KIET, KIPF, KIHASA, KICJ, KLRI. Korea Industrial Complexes / Tech Valleys: Pangyo Techno Valley·Dongtan·Gwanggyo·Songdo IBD·Yeouido·Gangnam·Sihwa·Banwol·Gumi·Ulsan·Changwon·Geoje·Yeosu·Onsan·Cheongju·Iksan·Gwangyang·POSCO Gwangyang Steel Mill·Asan Bay·Seosan·Songdo·Incheon Airport·Sejong·Cheongna·Geomdan. Korea Trade and Finance Infrastructure: Korea International Trade Association (KITA)·Korea Trade-Investment Promotion Agency (KOTRA)·Export-Import Bank of Korea (KEXIM)·Bank of Korea·Kookmin Bank·Shinhan·Hana·Woori·NH Nonghyup·IBK Industrial Bank·SC First Bank·Citi Bank Korea·HSBC Korea·DBS Korea — 14 Korean major banks and foreign banks. Korea K-POP / K-Content: HYBE·SM·YG·JYP 4 major entertainment companies·CJ ENM·tvN·MBC·KBS·SBS·EBS·YTN·Yonhap News TV·JTBC Korean broadcasting·NETFLIX Korea·Disney Plus·TVING·Wavve·Watcha·Coupang Play. Korea Gaming Industry: Nexon·NCsoft·Krafton·Netmarble·Kakao Games·Pearl Abyss·Com2uS·Gamevil·NHN·Smilegate·Webzen. Korea Automotive / Battery: Hyundai Motor·Kia·Genesis·LG Energy Solution·Samsung SDI·SK On·POSCO Future M·EcoPro·L&F battery cathode material suppliers. Korea Semiconductor: Samsung Electronics (HBM3E·HBM4)·SK hynix (HBM3E 12-Hi)·DB HiTek·SK siltron·SK Enpulse·Dongjin Semichem·Seoul Semiconductor·Simmtech·Samsung Display·LG Display.

Korea Standardization Infrastructure Mapping

Korea operates a comprehensive standards governance system through inter-ministerial cooperation. National Standards Council (under Prime Minister's Office, per Framework Act on National Standards Article 5) coordinates KATS (Korean Agency for Technology and Standards), MFDS (Ministry of Food and Drug Safety), MOTIE (Ministry of Trade, Industry and Energy), MSIT (Ministry of Science and ICT), MOIS (Ministry of the Interior and Safety), MOE (Ministry of Environment), MOHW (Ministry of Health and Welfare), MND (Ministry of National Defense), MCST (Ministry of Culture, Sports and Tourism), MOFA (Ministry of Foreign Affairs), MOJ (Ministry of Justice), and FSC (Financial Services Commission). Accreditation and Testing: KOLAS (Korea Laboratory Accreditation Scheme) accredits 800+ testing laboratories. KAS (Korea Accreditation System) accredits 50+ certification bodies. KTC (Korea Testing Certification), KTR (Korea Testing & Research Institute), KTL (Korea Testing Laboratory), and KCL (Korea Conformity Laboratories) provide conformance testing. Telecom and Cyber: KCC (Korea Communications Commission), KCA (Korea Communications Agency), TTA (Telecommunications Technology Association), IITP (Institute for Information & Communications Technology Planning & Evaluation), NIPA (National IT Industry Promotion Agency), KISA (Korea Internet & Security Agency), KCMVP (Korea Cryptographic Module Validation Program), NIS (National Intelligence Service), NSR (National Security Research Institute), and NCSC (National Cyber Security Center). National R&D Centers: KIST, ETRI, KAIST, Seoul National University, Yonsei University, Korea University, POSTECH, UNIST, GIST, DGIST, KISTI, KIER, KIMM, KRICT, KFRI, KRIBB. International Standards Cooperation: ISO TC/SC Korean secretariats, IEC TC/SC Korean secretariats, ITU-T Study Group Korean chairs, 3GPP RAN/SA Korean chairs, IEEE 802 Korean chairs, W3C Korea office, OASIS Korea office, IETF Korea cooperation, OECD CSTP, UN ESCAP, APEC SCSC Korean cooperation. Korean Industrial Standards (KS) Catalog: KS X (Information) 25,000+, KS A (Basic) 15,000+, KS B (Machinery) 25,000+, KS C (Electrical) 18,000+, KS D (Metallurgy) 12,000+, KS E (Mining) 5,000+, KS F (Construction) 18,000+, KS H (Food) 8,000+, KS I (Environment) 5,000+, KS J (Biology) 3,000+, KS K (Textile) 15,000+, KS L (Ceramics) 7,000+, KS M (Chemistry) 12,000+, KS P (Medical) 5,000+, KS Q (Quality Mgmt) 4,000+, KS R (Transport) 12,000+, KS S (Service) 3,000+, KS T (Packaging) 4,000+, KS V (Shipbuilding) 5,000+, KS W (Aerospace) 3,000+ — totaling 220,000+ Korean Industrial Standards. Key Acts: Personal Information Protection Act (Act 19234, effective Sept 15, 2024), Electronic Government Act, Electronic Signature Act, Act on Promotion of Information and Communications Network Utilization and Information Protection, Information and Communications Infrastructure Protection Act, Data Industry Act, Public Data Act, AI Framework Act (Act 20212, effective July 2026), Industrial Technology Innovation Promotion Act, Framework Act on Science and Technology — 70+ Korean standardization-related laws.

Korea Digital Transformation Detailed Mapping

Korea operates digital transformation through a comprehensive governance system. Digital Government: Digital Platform Government Committee (established September 2022, under the President)·Ministry of the Interior and Safety Digital Government Bureau·e-Government Support Center·Gov.kr·National Citizen Service·KDIS (Korea Digital Information Society)·NIA (National Information Society Agency)·MOIS (Ministry of the Interior and Safety). K-DNS Infrastructure: Korea Internet & Security Agency (KISA) Korea Internet Center·KISA DNS Root Server·KRNIC (Korea Network Information Center)·BGP Korea·National Cyber Security Center (NCSC)·KCC (Korea Communications Commission)·MSIT (Ministry of Science and ICT)·NIA·NIPA. Korean Cloud Infrastructure: KT Cloud·NAVER Cloud (NCloud)·Samsung SDS Cloud·LG U+ Cloud·NHN Cloud·Kakao Enterprise Cloud·SK Telecom Cloud·KISA Cloud Security Assurance Program (CSAP)·KCMVP-validated cloud·ISMS-P (Information Security & Personal Information Management System). Korean Security Certifications: KISA ISMS-P certification·KCMVP (Korean Cryptographic Module Validation Program)·NIS (National Intelligence Service) "National Cryptographic Technology Operation Standards"·NCSC "National Cyber Security Strategy 2024-2028"·CC (Common Criteria) Korean evaluation bodies·EAL4·EAL5·KS X ISO/IEC 15408·19790·24759 Korean Profile. Korean Data Standards: NIA AI Hub·National Data Standardization Committee·Statistics Korea (KOSTAT)·MyData 4 Designated Combination Specialists (Samsung SDS, KICI, KOSTAT, KFTC)·National Institute of Korean Language·National Law Information Center·National Spatial Information Platform·National Spatial Data Center·Korean Spatial Information Standards. Finance and Fintech Standards: FSC (Financial Services Commission)·FSS (Financial Supervisory Service)·FIU (Financial Intelligence Unit)·BOK (Bank of Korea)·FSEC (Financial Security Institute)·KFTC (Korea Financial Telecommunications)·KSD (Korea Securities Depository)·KRX (Korea Exchange) 8-agency cooperation. 5G/6G Communications Infrastructure: 5G subscribers 35 million (2024)·5G base stations 350,000·6G commercialization target 2028·5G dedicated networks 16 operators·6G Acceleration Council (MSIT, 2024). K-Content: KOCCA (Korea Creative Content Agency)·MCST (Ministry of Culture, Sports and Tourism)·KCA (Korea Communications Agency)·Korea Culture Information Service Agency·Korean Film Archive·Korea Publishing Industry Promotion Agency. Data 3 Acts (Personal Information Protection Act·Credit Information Act·Telecommunications Network Act, 2020 enforcement)·Data Industry Act (2021)·Public Data Act (2013)·AI Framework Act (2026)·Digital Platform Government Framework Act (2024 proposed) — Korea digital transformation core legislation.