SECUMAN Ontology and Shapes for Cybersecurity Risk Management in Medical Devices
A new ontology and associated shapes, known as SECUMAN, have been introduced to facilitate the representation and analysis of cybersecurity risk-management documentation for medical devices. This OWL-based vocabulary effectively models aspects such as security-risk context, assessment, control measures, and evaluation of residual risk, employing SHACL constraints to ensure structural integrity and adherence to the intended documentation framework. It aligns with VDE Spec 90025 and the related RISKMAN ontology, broadening their safety-focused approach to include cybersecurity elements like threat scenarios, protection goals, and attacker profiles. This initiative addresses the issue of current risk-management documents often being in semi-structured natural language, complicating consistency checks and certification. The relevance of cybersecurity risks for connected medical devices is increasing, potentially impacting patient safety. Details can be found in arXiv paper 2608.00698, noted as a cross-type submission.
Key facts
- SECUMAN ontology and shapes are proposed for cybersecurity risk management in medical devices.
- The ontology is OWL-based and models security-risk context, assessment, control measures, and residual-risk evaluation.
- SHACL constraints are used to check structural completeness and conformity.
- Aligned with VDE Spec 90025 and the RISKMAN ontology and shapes.
- Extends safety-oriented approach to cybersecurity concepts like threat scenarios, protection goals, and attacker profiles.
- Addresses issues with semi-structured natural language text in risk-management files.
- Cybersecurity risks are increasingly relevant for connected medical devices and impact patient safety.
- Paper available on arXiv with ID 2608.00698.
Entities
Institutions
- arXiv
- VDE Spec 90025