Information Sharing and Analysis Organization
A self-organized entity, authorized under the Cybersecurity Act of 2015, that gathers, analyzes, and shares cybersecurity threat information among members, including in the health sector.
Definition
An ISAO is a voluntary organization created to gather, analyze, and disseminate cybersecurity threat information among its members and, where appropriate, with government partners. The concept was formalized in the Cybersecurity Act of 2015 and Executive Order 13691, which directed the Department of Homeland Security (now largely under CISA) to support the ISAO Standards Organization in developing voluntary standards for ISAO formation and operation. Unlike sector-specific Information Sharing and Analysis Centers (ISACs), which are organized around critical infrastructure sectors defined in Presidential Policy Directive 21, an ISAO can be organized around any community of interest, geography, or shared risk profile, making it a more flexible model. In MedTech, Health-ISAC operates as the principal health sector ISAC, and manufacturers may separately participate in ISAOs to fulfill FDA's expectation, stated in postmarket cybersecurity guidance, that manufacturers participate in an information sharing organization to receive and disseminate vulnerability and threat intelligence.What this means in practice
FDA guidance references ISAO participation as a marker of a mature cybersecurity program and, for cyber devices under Section 524B, coordinated vulnerability disclosure processes commonly route disclosures through an ISAO or ISAC before public release. CISA maintains a list of standards developed by the ISAO Standards Organization covering ISAO creation, information sharing agreements, and privacy protections for shared data.- •Confusing an ISAO with an ISAC; ISACs are sector-specific and often more mature, while ISAOs can form around any shared interest and vary widely in rigor.
- •Assuming ISAO membership alone satisfies FDA's postmarket cybersecurity expectations without an internal vulnerability management process to act on shared intelligence.
- •Sharing threat data without following the liability-protection conditions in the Cybersecurity Act of 2015, which can expose the sharing entity to antitrust or privacy risk.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsMember-driven nonprofit that operates the trusted sharing community for cyber and physical threat intelligence across the healthcare sector.
International harmonized guidance on medical-device cybersecurity from the IMDRF Cybersecurity Working Group.
FDA's framework for ongoing vulnerability monitoring, risk assessment, and remediation of medical device cybersecurity issues after a device is on the market.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
More in Industry Bodies
· Same categoryStandards body for medical instrumentation; co-publisher of ISO/IEC adoptions.
U.S. trade association for the medical device and diagnostics industry.
Diagnostics-focused division of AdvaMed.
US-based consensus standards organization whose documents establish widely used analytical and clinical laboratory performance evaluation protocols for IVDs.
Where this term appears across MedTech Terms.
Sources
3 sourcesEvery citation below opens the original document. Each is graded against our source-tier hierarchy so you can see what rests on binding law versus commentary.
- 1CISA, Information Sharing and Analysis Organizations (ISAOs)Tier 2 UncheckedCISAcisa.gov
- 2Cybersecurity Act of 2015 (Title I)Tier 1 UncheckedCongress.govcongress.gov
- 3FDA Postmarket Management of Cybersecurity in Medical Devices (2016)Tier 2 UncheckedFDAfda.gov
Inline markers like [1] jump to the matching reference above.