CHINESE JOURNAL OF MEDICINAL GUIDE >
Exploration of the Construction and Operation of the National Medical Device Cybersecurity Vulnerability Database
Received date: 2025-08-01
Revised date: 2025-08-04
Accepted date: 2025-08-05
Online published: 2025-08-06
Currently, cybersecurity issues have become one of the key factors restricting the development of the medical device industry. Promoting vulnerability governance and strengthening the safety management of medical devices throughout their entire life cycle is particularly important. Cybersecurity vulnerabilities are becoming an important national strategic resource. The construction and operation of a national medical device cybersecurity vulnerability database is a fundamental and strategic project in the field of medical device cybersecurity in China. It plays an irreplaceable and important role in ensuring patient life safety and privacy, maintaining medical order and social stability, and promoting the healthy development of the medical device industry. This study, based on an analysis of the current situation of medical devices cybersecurity vulnerability governance, explores the key issues and chanenges existing in the construction and operation of the national medical device cybersecurity vulnerability database, such as insufficient awareness, scattered management, limited technical means, and the technology, data, talent, and policies and regulations in the governance of cybersecurity vulnerabilities. The study systematically summarizes the principles for establishing the national medical device cybersecurity vulnerability database, including the principles of authority, completeness, accuracy, timeliness, and security. It also covers key technologies, such as vulnerability collection and verification, vulnerability analysis and evaluation, vulnerability early warning and release, and vulnerability repair and management. Additionally, the construction process is outlined, including planning and design, data collection and organization, platform construction and development, testing and optimization, and launch operation and maintenance. The operation and management model is another focus, which includes organizational structure and personnel management, vulnerability information management and services, cooperation and exchange, supervision, management, and evaluation. The aim is to build a vulnerability database platform that is authoritative, complete, accurate, timely, and secure, in order to address the threats posed by cybersecurity vulnerabilities in medical devices. At the same time, this study aims to provide theoretical support and practical guidance for the improvement of China's medical device cybersecurity protection system.
CHEN Feng
.
Exploration of the Construction and Operation of
the National Medical Device Cybersecurity Vulnerability Database
[1] 国家药品监督管理局.医疗器械监督管理条例 [EB/OL].(2024-12-06)[2025-05-05].https://www.nmpa.gov.cn/xxgk/fgwj/flxzhfg/20250416172904188.html.
[2] 王晨希.医疗器械网络安全质量控制探讨[J].中国医疗设备,2021,(9):23-27.
[3] FDA. Cybersecurity Vulnerabilities with Certain Patient Monitors from Contec and Epsimed: FDA Safety Communication[EB/OL].(2025-01-30)[2025-05-05].https://www.fda.gov/medical-devices/safety-communications/cybersecurity-vulnerabilities-certain-patient-monitors-contec-and-epsimed-fda-safety-communication.
[4] CISA. FACT SHEET Contec CMS8000 Contains a Backdoor[EB/OL].(2025-01-30)[2025-05-05].https://www.cisa.gov/resources-tools/resources/contec-cms8000-contains-backdoor.
[5] CISA. Contec CMS8000 Contains a Backdoor[EB/OL].(2025-01-30)[2025-05-05].https://www.cisa.gov/sites/default/files/2025-01/fact-sheet-contec-cms8000-contains-a-backdoor-508c.pdf.
[6] CVE. CVE-2025-0683[EB/OL].(2025-01-30)[2025-05-05].https://www.cve.org/CVERecord?id=CVE-2025-0683.
[7] 曹明,任望.践行总体国家安全观,推动网络安全漏洞治理体系建设[J].中国信息安全,2022,(6):30-33.
[8] 国家药品监督管理局医疗器械技术审评中心.国家药监局器审中心关于发布医疗器械网络安全注册审查指导原则(2022年修订版)的通告(2022年第7号)[EB/OL].(2025-01-30)[2025-05-05].https://www.cmde.org.cn//xwdt/shpgzgg/gztg/20220309085600367.html.
[9] 林香,侯建勋,古锐鹏,等.浅谈医疗器械软件网络安全[J].网络安全技术与应用,2024,(8):109-110.
[10] 姜淑杨,鲍磊磊,缪明榕.计算机网络安全漏洞及其管理研究[J].电子元器件与信息技术,2019,3(7):14-17.
[11] 孙成昊,杨一未,易锦,等.漏洞分类分级标准在国家信息安全漏洞库的应用[J].信息技术与标准化,2022,(5):82-86.
[12] 王晟,张通凯,李超峰.网络安全漏洞管理与漏洞情报库建设分析[J].电信工程技术与标准化,2023,36(12):65-68.
[13] 黄海波,杨帅锋,杨杰,等.从国家漏洞数据库建设看美国网络安全漏洞管理体系[J].保密科学技术,2020,(2):22-26.
[14] 曹明,任望.坚持总体国家安全观加快推进国家网络安全漏洞治理赋能新质生产力发展[J].中国信息安全,2024,(5):20-22.
[15] 赵精武.网络安全漏洞挖掘的法律规制研究[J].暨南学报(哲学社会科学版),2017,39(5):24-32.
/
| 〈 |
|
〉 |