15 Security
The f
ollowing secons provide informaon about important security consideraons for using the
system.
15.1 Customer Responsibilies
Philips Medical Systems recognizes that the security of its products is an important part of your facility's
in-depth security strategy. However, these benets can only be realized if you implement a
comprehensive, mul-layered strategy (including policies, processes, and technologies) to protect
informaon and systems from external and internal threats.
Following industry-standard pracce; your strategy should address physical security, operaonal
security, procedural security, risk management, security policies, and conngency planning. The
praccal implementaon of technical security elements varies by site and may employ a number of
technologies, including rewalls, virus-scanning soware, authencaon technologies, etc.
As with any computer-based system, protecon must be provided such that rewalls and/or other
security devices are in place between the medical system and any externally accessible systems.
The USA Veterans Administraon has developed a widely used Medical Device Isolaon Architecture
for this purpose. Such perimeter and network defenses are essenal elements in a comprehensive
medical device security strategy.
Addional security and privacy informaon can be found on the following website:
www.philips.com/productsecurity
15.1.1 Risks Related to Security
There are several risks related to security that should be assessed.
• The device is not intended as a long term storage device. Customers are advised to export a study
when the procedure ends to ensure availability of the related data. For more informaon, see
Exporng Data (page 147). The export funcon can be congured to occur automacally.
• To ensure condenality, integrity, and availability of the device and related data, the following
recommendaons are made:
– Implement network and physical access controls to limit the likelihood of compromise. For
more informaon, see Customer Responsibilies (page 266).
– Enable the security controls that are embedded into the device. For more informaon, see
System Administraon (page 229).
• It is recommended that the manufacturer's product security recommendaons are monitored on a
regular basis. For more informaon, see Malware Protecon (page 267).
The assessment should be repeated whenever changes are made to the network. These changes
include:
• Changes in the network conguraon
• Connecon of addional items to the network
• Disconnecon of items from the network
• Updates or upgrades to items that are connected to the network
Security Customer Responsibilies
Azurion Release 1.2 Ins
trucons for Use 266 Philips Healthcare 4522 203 52421