
Medical Devices
Medical device development faces multiple challenges, including the rising threat of cyberattacks, extensive regulatory requirements, the need for agile development, efficient process management, and pressure to reduce R&D costs.
Vector Consulting provides professional support in the efficient usage of standards for regulatory compliance to FDA and MDCG guidelines, development standards like IEC 62304 (life-cycle), ISO 14971 (risk management), IEC 60601 (product development), etc., in agile methodologies as well as support in cybersecurity by offering independent risk-oriented Grey-Box Penetration Test of medical devices.
To address these demands, we deliver highly aligned development and life-cycle processes including robust cybersecurity and safety measures from design to deployment and SW-update management.
This includes strengthening system architecture, structured risk management, streamlining requirements and development, traceability, and cost-effective R&D while ensuring safety and security throughout the product lifecycle.
Solutions for Medical
- Standards and Regulatory Compliance: Consulting and compliance support for FDA guidelines, MDCG regulations, IEC 60601, IEC 62304, ISO 14971 etc.
- Risk Management: Systematic risk assessment methods using HARA and TARA enabling low residual risk.
- Requirements Engineering and Product Management: Systematic requirements engineering to ensure consistency of requirements, product usability, risk management, system reliability, and regulatory compliance.
- IT workflows & Agile for Medical: Streamline operations using CI/CT/CD (DevOps), boost efficiency, and reduce cycle times using agile methodologies.
- Supplier Management: Efficiently manage suppliers and foster global collaborations.
- Code Quality Analysis: Ensure code integrity and reliability for your medical software.
- Cybersecurity Support: Cybersecurity Validation with independent risk-oriented Grey-Box Penetration Test safeguards systems against threats, while Security-by-Lifecycle ensures post-market surveillance through continuous monitoring, incident response, and vulnerability management.
- Trainings: Individual trainings and training programs for customer specific competence development.
Standards
Vector Consulting supports implementing the most relevant standards required to comply to FDA and MDR/IVDR:
- Quality Assurance with ISO 13485 (Medical devices, Quality management systems, Requirements for regulatory purposes). Based on traditional quality management standards and adapted to the medical domain.
- IEC 62304 (Medical device software, software life-cycle processes) specifies life-cycle requirements for the development of medical software is building upon the widely used ISO/IEC 12207. It enhances life-cycle management by governance and observability, and mapping to specific medical needs.
- ISO 14971 (Medical devices, Application of risk management to medical devices, medical risk management process) consists of several steps for the design, development and production of every medical device.
- IEC 62366 (medical devices, application of usability engineering to medical devices) is the primary standard and specifies usability requirements for the development of medical devices, including negative use cases such as misuse and abuse. Usability matters for medical devices because they combine highest safety demands with lots of direct human interaction by a variety of stakeholders ranging from doctors to nurses, and from administrators to technicians.
- Application of general-purpose standards to medical software development, such as test-management according to ISO/IEC/IEEE 29119 (software and systems engineering, software testing) for software testing, IEC 61508 for functional safety of electronic components and ISO 27001 which provides a framework for organizations to establish, implement, operate, monitor, review, maintain and continually improve the Information Security Management System (ISMS).
Medical Security
Security of medical devices is of prime importance as these deal with the health and data of people.
Examples of cyberattacks on medical devices: eavesdropping, data leakage, data corruption, password attacks, sensor confusion, vulnerabilities in application, deceiving forensic examiners (repudiation).
Most security attacks are process and implementation related. Therefore, security is about identification of the attack surface starting with Security Requirements and risk mitigation across the Lifecycle.
Vector security solutions for medical is about systematic risk- oriented methodologies for ensuring that security efforts are focused on most significant risks.
Security by Design
- Promoted by safety-driven development
- Critical systems should be "Secure by Design"
- Frontloading with requirements, bottom-up protection and security engineering
Security by Lifecycle
- Promoted by experience in IT and Software-intensive systems
- Add-on to traditional "security-by-design" approach
- Counters dynamic changes and evolution of threats and security mechanisms


