mdi Consultants now offers software penetration testing to demonstrate full conformance with cybersecurity requirements under ISO 27001 and FD&C Act section 524B “Ensuring Cybersecurity of Medical Devices” for businesses engaged in software usage for their medical devices and other related regulatory products produced under ISO and FDA standards.
The FDA requires that all manufacturers of “cyber devices,” or devices subject to the threat of electronic attack, take steps to mitigate the risk of a cyberattack. Penetration testing under a controlled environment will provide the necessary validation studies to affirm to the regulatory and/or certifying agencies that vulnerabilities which may leave a system open to hacking have been found and mitigated. The studies will be conducted by a cybersecurity firm with an extensive background in penetration testing, code review, and configuration audit in fields such as finance, critical infrastructure, and government services.
The test firm will work closely with the clients’ IT team or vendors, utilizing the most up-to-date methodology for testing of Web applications, mobile applications, appliances/hardware, and network devices. Black box, grey box, and white box methodologies can be employed in the testing scenarios. Following the test, the cybersecurity firm will produce a report detailing observed vulnerabilities and recommendations for action on the client’s part to strengthen their software packages.