---
title: "Connected &amp; Cyber-Physical Devices - MedTech Ecosystems"
description: "The full cybersecurity stack for connected medical devices: SBOMs, threat modeling, secure-by-design, vulnerability disclosure, and the FDA, IMDRF, and HSCC…"
lang: en
json-ld:
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

[All ecosystems](/ecosystems)

Ecosystem 

# Connected & Cyber-Physical Devices

The full cybersecurity stack for connected medical devices: SBOMs, threat modeling, secure-by-design, vulnerability disclosure, and the FDA, IMDRF, and HSCC guidance that defines today's expectations.

64 terms

## Regulatory1 

-   [Breakthrough Device Designation(BDD) ](/terms/breakthrough-device)

## Cybersecurity60 

-   [AAMI SW96 ](/terms/aami-sw96)
-   [AAMI TIR57 ](/terms/aami-tir57)
-   [AAMI TIR97(TIR97) ](/terms/aami-tir97)
-   [Brainjacking ](/terms/brainjacking)
-   [CISA Known Exploited Vulnerabilities Catalog(KEV) ](/terms/kev)
-   [Code Signing ](/terms/code-signing)
-   [Common Vulnerabilities and Exposures(CVE) ](/terms/cve)
-   [Common Vulnerability Scoring System(CVSS) ](/terms/cvss)
-   [Common Weakness Enumeration(CWE) ](/terms/cwe)
-   [Coordinated Vulnerability Disclosure(CVD) ](/terms/cvd)
-   [Cryptographic Agility ](/terms/crypto-agility)
-   [CycloneDX ](/terms/cyclonedx)
-   [De-Identification of Health Data ](/terms/de-identification)
-   [FedRAMP(FedRAMP) ](/terms/fedramp)
-   [Hardcoded Credentials ](/terms/hardcoded-credentials)
-   [Hardware Root of Trust(HRoT) ](/terms/hardware-root-of-trust)
-   [Health Industry Cybersecurity Practices(HICP) ](/terms/hicp)
-   [Health Information Sharing and Analysis Center(H-ISAC) ](/terms/h-isac)
-   [Healthcare and Public Health Cybersecurity Performance Goals(HPH-CPG) ](/terms/hph-cpg)
-   [HIPAA(HIPAA) ](/terms/hipaa)
-   [HITECH Act(HITECH) ](/terms/hitech-act)
-   [HITRUST CSF(HITRUST) ](/terms/hitrust)
-   [HSCC Joint Security Plan(HSCC JSP) ](/terms/hscc-jsp)
-   [ICS Medical Advisory(ICSMA) ](/terms/ics-medical-advisory)
-   [IEC 80001-1 ](/terms/iec-80001)
-   [IEC 81001-5-1 ](/terms/iec-81001-5-1)
-   [IMDRF Principles and Practices for Medical Device Cybersecurity ](/terms/imdrf-cyber-principles)
-   [ISO/IEC 27001(ISO 27001) ](/terms/iso-27001)
-   [Legacy Device Cybersecurity ](/terms/legacy-device-cyber)
-   [LINDDUN ](/terms/linddun)
-   [Manufacturer Disclosure Statement for Medical Device Security(MDS2) ](/terms/mds2)
-   [Medhacking ](/terms/medhacking)
-   [Medjacking ](/terms/medjacking)
-   [MITRE ATT&CK(ATT&CK) ](/terms/mitre-attack)
-   [MITRE D3FEND(D3FEND) ](/terms/mitre-d3fend)
-   [NIST Cybersecurity Framework(NIST CSF) ](/terms/nist-csf)
-   [NIST IR 8473, Cybersecurity Framework Profile for HPH(NIST IR 8473) ](/terms/nist-cswp-35)
-   [NIST SP 800-53 / 800-171(NIST 800-53/171) ](/terms/nist-800-53)
-   [Over-the-Air Updates(OTA) ](/terms/ota-updates)
-   [OWASP IoT and Embedded Application Security ](/terms/owasp-iot)
-   [Patchability ](/terms/patchability)
-   [Penetration Testing ](/terms/pen-test)
-   [PHI and ePHI ](/terms/phi-ephi)
-   [Premarket Cybersecurity Submission ](/terms/premarket-cybersecurity)
-   [Refuse to Accept (Cybersecurity)(RTA (cyber)) ](/terms/rta-cyber)
-   [SAST and DAST ](/terms/sast-dast)
-   [Section 524B of the FD&C Act(524B) ](/terms/section-524b)
-   [Secure Boot ](/terms/secure-boot)
-   [Secure Product Development Framework(SPDF) ](/terms/spdf)
-   [Secure Software Development Framework(SSDF) ](/terms/ssdf)
-   [Side-Channel Attack ](/terms/side-channel)
-   [SOC 2 ](/terms/soc-2)
-   [Software Bill of Materials(SBOM) ](/terms/sbom)
-   [Software Safety Case ](/terms/software-safety-case)
-   [SPDX(SPDX) ](/terms/spdx)
-   [STRIDE Threat Model(STRIDE) ](/terms/stride)
-   [Supply-chain Levels for Software Artifacts(SLSA) ](/terms/slsa)
-   [Threat Modeling ](/terms/threat-modeling)
-   [Vulnerability Exploitability eXchange(VEX) ](/terms/vex)
-   [Zero Trust Architecture(ZTA) ](/terms/zero-trust)

## Clinical & Trials1 

-   [Serious Adverse Event(SAE) ](/terms/sae)

## Software & AI2 

-   [Predetermined Maintenance vs PCCP ](/terms/predetermined-maintenance)
-   [Secure-by-Design (Devices) ](/terms/secure-by-design)

### Other ecosystems

[Regulated Pathways](/ecosystems/regulated-pathways)[AI / ML in Devices](/ecosystems/ai-ml)[Software Lifecycle](/ecosystems/software-lifecycle)[Quality System](/ecosystems/quality-system)[Clinical Evidence](/ecosystems/clinical-evidence)[Post-Market & Safety](/ecosystems/post-market-safety)[Global Markets](/ecosystems/global-markets)[Hospital Buyer & Reimbursement](/ecosystems/hospital-buyer)[Startup Lifecycle](/ecosystems/startup-lifecycle)[Strategic Landscape](/ecosystems/strategic-landscape)[Manufacturing & Supply](/ecosystems/manufacturing-supply)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)