AAMI TIR57
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
Definition
AAMI TIR57:2016 "Principles for medical device security - Risk management" is a technical information report that adapts general security risk-management principles to medical devices, with explicit bridges to ISO 14971 (safety risk management) and IEC 80001 (network risk). TIR57 is the MedTech-specific reference for integrating cybersecurity risk into the existing safety risk management file rather than running it as a separate process.What this means in practice
TIR57 is most useful as the bridge document that lets MedTech risk and security teams speak the same language. Together with TIR97 (post-market security risk management) it forms the AAMI cybersecurity playbook.- •Treating cybersecurity risk and safety risk as parallel processes producing two different files.
- •Ignoring TIR97 for post-market - TIR57 is the design-side reference, TIR97 covers the operational side.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsInternational standard for risk management of IT networks that incorporate medical devices.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
A documented, risk-based set of processes that build cybersecurity into a medical device across its full lifecycle.
More in Cybersecurity
· Same categoryA structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Where this term appears across MedTech Terms.
Primary references
3 sources- 1
FDA Cybersecurity Guidance (Sept 2023)VerifiedFDAfda.gov
- 2
HSCC - Health Sector Coordinating CouncilVerifiedHSCChealthsectorcouncil.org
- 3
CISA - Healthcare and Public Health SectorVerifiedCISAcisa.gov
Inline markers like [1] jump to the matching reference above.