SlideShare ist ein Scribd-Unternehmen logo
1 von 30
Downloaden Sie, um offline zu lesen
Risk Management and IEC 62304
Applying IEC 62304 Risk Management in Aligned Elements
February 2015
Elements
Medical Devices and Risk Management
 Workflows and functions drives
Risk Management
 Risk Management drives Design
 Design and Risk Management
are interdependent
 Traceability connects Design and
Risk Management
Workflows
&
Functions
Hazardous
Situation
Risk
Risk
Control
Design
Elements
Risk Management and Regulations
ISO 13485
QMS
ISO 14971
Risk
Management
IEC 62304
Software
Lifecycle
IEC 60601-1
Security in
Electromedical
devices
IEC 62366
Usability
Refers to
Refers to
Refers to
Elements
Risk Management and Regulations
ISO 13485
QMS
ISO 14971
Risk
Management
IEC 62304
Software
Lifecycle
Design &
Maintenance of
software in MD
IEC 60601-1
Security in
Electromedical
devices
IEC 62366
Usability
Affects
Affects
Affects
Elements
General Concepts of Risk Assessments
 Identify Hazards
 Evaluate Risks (likelihood &
consequences)
 Perform Risk Reduction
 Evaluate residual Risks
Elements
Risk Management in IEC 62304
 Risk drives the level of
documentation required
 Software Safety Classification of
architectural artifacts
 Risk inheritance in architecture
 Systematic risks => 100% probability
of occurrence
 Affects not only development, also
affects maintenance
Software System
Class C
Software Item
Class C
Software Unit
Class C
Software Unit
Class B
Software Item
Class A
Software Item
Class A
Elements
Documenting Medical Device Development
 Increasing number of regulations
 Development documentation is difficult,
complex and resource intensive to manage
 Aligned Elements helps you “build” a
consistent and complete documentation
 Free up valuable resources from
cumbersome administrative tasks
Elements
Aligned Elements – a medical device ALM
 Manages the DHF Design Control Items
 Version Control + Traceability + Documents
 Integrated Risk Management
 Real-time quality checks on content
 Ensures completeness and consistency
Elements
FMEA
 Concerns Safety & “Business”
 Widely adopted technique
 Versatile usage
 Probability x Severity x
Visibility
Preliminary Hazard Analysis
 Concerns Safety / Harm only
 In the early design phase
 Full device implementation is
not required
 Aligned with ISO 14971
Risk Assessments in Aligned Elements
Elements
Preliminary Hazard Analysis (PHA) Overview
Cause
(with probability)
Harm
(with severity)
Hazardous
Situation
Risk Control
Measure
Hazard
Elements
Risk Analysis Element
PHA in Aligned Elements
Cause
Harm
(with severity)
Hazardous
Situation
Risk Control
Measure
Reusable Elements
Probability of
Harm
Potential
Hazard
Elements
PHA in Aligned Elements
Elements
Aligned Elements PHA in Word
Elements
Risk Analysis
PHA and Traceability
Cause 1
Measure 1
Cause 2
Cause 3
Measure 2
Measure 3
SW Use Case
HW Function
SW Item
SW
Requirement
Instructions
For Use
HW
Specification
Potential
Hazards
Elements
Aligned Elements as Risk Management Tool
 Automatic calculation of RPN
 Automatic checks of RPN against
thresholds
 Reuse of Harms, Causes and Measures
 Measures grouped and sorted according
to Risk Reduction Type
 Highlighting of insufficiently controlled
risks
 Highlighting of unimplemented Measures
 Risk elements integrated with Design
trace landscape
Elements
Risk Management in IEC 62304
Cause
Hazardous
Situation
Risk Reduction
Measure
Hazard Software Item
Software
Requirement
Verification
IEC 62304 – 7.3.3 Document Traceability
Elements
Risk Analysis
IEC 62304 PHA in Aligned Elements
Cause
Measure
Software Item
(with classification)
SW
Requirement
Verification
Harm
Does classification
match Harms in the
Risk Analysis?
Hazardous
Situation
Are Risk Control
Measures implemented
and verified?
Elements
Software Safety Classification (SSC) in Aligned
Automatic Rule Checks:
 Is SSC consistent with severity of
(implicitly) linked Harms?
 Is SSC consistent with classification
of dependent Software Items?
Specify Rules:
 SSC inheritance of Software Items
 Software Item must trace to Cause
 Connect Severity of Harm with SSC
Severity of Harm Classification
5 or 4 C
3 or 2 B
1 A
Elements
Risk Analysis
SSC example in Aligned Elements
Cause
Software Item
(Class B)
SW Unit
(Class C)
Harm
Severity: 5
Not OK!
Not OK!
Severity of Harm Classification
5 or 4 C
3 or 2 B
1 A
Elements
IEC 62304 and Probability in Risk Management
 Software error probability is difficult
to estimate
 Software errors are systematic
 IEC 62304 claims that Software
Safety Classification shall not
depend on probability, only on harm
 Assume Probability of software
error = 100% (section 4.3. a)
 Can we reduce the probability with
our Risk Control Measures?
Elements
Use two probabilities:
 Probability of Hazardous Situation (P1)
 Probability of Harm (P2)
Usage:
 P2 can be estimated by professional (e.g.
a Medical Doctor)
 Adapt risk policy and thresholds
 Risk Control Measures affect P1 and P2
Using two probabilities
Software
Error
Hazardous
Situation
Harm
P1
P2
Elements
Two probabilities in Aligned Elements
Elements
Two probabilities in Aligned Elements
Elements
Architecture vs. Functional Usage
 Architecture: Hierarchical
decomposition of Software
into Items and Units
 Software risk emanates from
how we use the software
i.e. in which functional
context we use the software
items
 Functional use cuts across
the architecture
Use Case
1
(high risk)
Use Case
2
(mid risk)
Use Case
3
(low risk)
SW Item 1
SW Item
2
SW Item 4
SW Item
3
SW Unit
1
SW Unit
2
SW Unit
3
Elements
The Matrix Model in IEC 62304
Elements
Matrix Model in Aligned Elements
 Write Use Cases from SW Reqs
 Perform Risk Analysis on Use Cases
 Generate Causes from Use Cases
where applicable
 Create Architecture
 Map Use Cases to Software Items by
connecting Software Items to existing
Causes
 If applicable, generate new Causes
from Software Items and map back to
User CasesRisk Analysis
Causes
Software
Requirements
Harm
Hazardous
Situation
Software
Items
Elements
Software Problem Resolution Process
 Record Problem Report
 Identify Causes and perform risk
analysis
 Evaluate Risk
 Create Change Request (if
applicable)
 Verify Change
Risk AnalysisCause
Measure
Problem
Report
Change
Request
Verification
Harm Hazardous
Situation
Elements
Aligned Elements IEC 62304 Package
 Full template set for all IEC 62304 Artifacts
 Includes clear references to applicable sections in IEC 62304
 Full usage of Aligned Elements automatic consistency checks
 Integrated Checklists and Review Generators
 Preconfigured Word reports
 Preconfigured Trace Tables
 Preconfigured Queries
Elements
Maximal results, minimal effort
Thank You!Aligned AG
Binzmühlstrasse 210
CH-8050 Zürich
Switzerland
t +41 (0)44 312 50 20
f +41 (0)44 312 50 20
m info@aligned.ch
w www.aligned.ch

Weitere ähnliche Inhalte

Was ist angesagt?

Risk Management in Medical Device Development
Risk Management in Medical Device DevelopmentRisk Management in Medical Device Development
Risk Management in Medical Device DevelopmentIntland Software GmbH
 
EU Medical Device Regulatory Framework_Dec, 2022
EU Medical Device Regulatory Framework_Dec, 2022EU Medical Device Regulatory Framework_Dec, 2022
EU Medical Device Regulatory Framework_Dec, 2022Levi Shapiro
 
Software Failure Modes Effects Analysis Overview
Software Failure Modes Effects Analysis OverviewSoftware Failure Modes Effects Analysis Overview
Software Failure Modes Effects Analysis OverviewAnn Marie Neufelder
 
ISO 14971:2019 and ISO/TR 24971 Risk Management Update
ISO 14971:2019 and ISO/TR 24971 Risk Management UpdateISO 14971:2019 and ISO/TR 24971 Risk Management Update
ISO 14971:2019 and ISO/TR 24971 Risk Management UpdateZafirios Gourgouliatos, Ph.D.
 
General Principals Of Software Validation
General Principals Of Software ValidationGeneral Principals Of Software Validation
General Principals Of Software Validationstaciemarotta
 
Software FMEA and Software FTA – An Effective Tool for Embedded Software Qual...
Software FMEA and Software FTA – An Effective Tool for Embedded Software Qual...Software FMEA and Software FTA – An Effective Tool for Embedded Software Qual...
Software FMEA and Software FTA – An Effective Tool for Embedded Software Qual...Mahindra Satyam
 
Revised IEEE 1633 Recommended Practices for Software Reliability
Revised IEEE 1633 Recommended Practices for Software ReliabilityRevised IEEE 1633 Recommended Practices for Software Reliability
Revised IEEE 1633 Recommended Practices for Software ReliabilityAnn Marie Neufelder
 
Bi-dimensional risk analysis - safety&security -software medical device
 Bi-dimensional risk analysis - safety&security -software medical device Bi-dimensional risk analysis - safety&security -software medical device
Bi-dimensional risk analysis - safety&security -software medical deviceAntonio Bartolozzi
 
ISO13485 Awareness Training (9-10th November 2021).pptx
ISO13485 Awareness Training (9-10th November 2021).pptxISO13485 Awareness Training (9-10th November 2021).pptx
ISO13485 Awareness Training (9-10th November 2021).pptxssuserd5e406
 
Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview Greenlight Guru
 
Iso 14971 2019
Iso 14971 2019Iso 14971 2019
Iso 14971 2019Suhas R
 
The Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMDThe Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMDJanel Heilbrunn
 
QMSR Harmonization: The Future of FDA's Quality Management System Regulation
QMSR Harmonization: The Future of FDA's Quality Management System RegulationQMSR Harmonization: The Future of FDA's Quality Management System Regulation
QMSR Harmonization: The Future of FDA's Quality Management System RegulationGreenlight Guru
 
Quality management in software engineering
Quality management in software engineeringQuality management in software engineering
Quality management in software engineeringZain ul Abideen
 
Breakout Session: Cybersecurity in Medical Devices
Breakout Session: Cybersecurity in Medical DevicesBreakout Session: Cybersecurity in Medical Devices
Breakout Session: Cybersecurity in Medical DevicesHealthegy
 
Quality Control for Medical Device Software - It Arena Lviv Presentation
Quality Control for Medical Device Software - It Arena Lviv PresentationQuality Control for Medical Device Software - It Arena Lviv Presentation
Quality Control for Medical Device Software - It Arena Lviv PresentationRoman Lavriv
 
Risk assessment for computer system validation
Risk assessment for computer system validationRisk assessment for computer system validation
Risk assessment for computer system validationBangaluru
 
Iso 13485:2016
Iso 13485:2016Iso 13485:2016
Iso 13485:2016Suhas R
 
What You Need to Know About Medical Electrical Standards Updates (and how the...
What You Need to Know About Medical Electrical Standards Updates (and how the...What You Need to Know About Medical Electrical Standards Updates (and how the...
What You Need to Know About Medical Electrical Standards Updates (and how the...Greenlight Guru
 
Human factor standards and usability (by Ed Israelski)
Human factor standards and usability (by Ed Israelski)Human factor standards and usability (by Ed Israelski)
Human factor standards and usability (by Ed Israelski)Stella Tsank
 

Was ist angesagt? (20)

Risk Management in Medical Device Development
Risk Management in Medical Device DevelopmentRisk Management in Medical Device Development
Risk Management in Medical Device Development
 
EU Medical Device Regulatory Framework_Dec, 2022
EU Medical Device Regulatory Framework_Dec, 2022EU Medical Device Regulatory Framework_Dec, 2022
EU Medical Device Regulatory Framework_Dec, 2022
 
Software Failure Modes Effects Analysis Overview
Software Failure Modes Effects Analysis OverviewSoftware Failure Modes Effects Analysis Overview
Software Failure Modes Effects Analysis Overview
 
ISO 14971:2019 and ISO/TR 24971 Risk Management Update
ISO 14971:2019 and ISO/TR 24971 Risk Management UpdateISO 14971:2019 and ISO/TR 24971 Risk Management Update
ISO 14971:2019 and ISO/TR 24971 Risk Management Update
 
General Principals Of Software Validation
General Principals Of Software ValidationGeneral Principals Of Software Validation
General Principals Of Software Validation
 
Software FMEA and Software FTA – An Effective Tool for Embedded Software Qual...
Software FMEA and Software FTA – An Effective Tool for Embedded Software Qual...Software FMEA and Software FTA – An Effective Tool for Embedded Software Qual...
Software FMEA and Software FTA – An Effective Tool for Embedded Software Qual...
 
Revised IEEE 1633 Recommended Practices for Software Reliability
Revised IEEE 1633 Recommended Practices for Software ReliabilityRevised IEEE 1633 Recommended Practices for Software Reliability
Revised IEEE 1633 Recommended Practices for Software Reliability
 
Bi-dimensional risk analysis - safety&security -software medical device
 Bi-dimensional risk analysis - safety&security -software medical device Bi-dimensional risk analysis - safety&security -software medical device
Bi-dimensional risk analysis - safety&security -software medical device
 
ISO13485 Awareness Training (9-10th November 2021).pptx
ISO13485 Awareness Training (9-10th November 2021).pptxISO13485 Awareness Training (9-10th November 2021).pptx
ISO13485 Awareness Training (9-10th November 2021).pptx
 
Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview
 
Iso 14971 2019
Iso 14971 2019Iso 14971 2019
Iso 14971 2019
 
The Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMDThe Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMD
 
QMSR Harmonization: The Future of FDA's Quality Management System Regulation
QMSR Harmonization: The Future of FDA's Quality Management System RegulationQMSR Harmonization: The Future of FDA's Quality Management System Regulation
QMSR Harmonization: The Future of FDA's Quality Management System Regulation
 
Quality management in software engineering
Quality management in software engineeringQuality management in software engineering
Quality management in software engineering
 
Breakout Session: Cybersecurity in Medical Devices
Breakout Session: Cybersecurity in Medical DevicesBreakout Session: Cybersecurity in Medical Devices
Breakout Session: Cybersecurity in Medical Devices
 
Quality Control for Medical Device Software - It Arena Lviv Presentation
Quality Control for Medical Device Software - It Arena Lviv PresentationQuality Control for Medical Device Software - It Arena Lviv Presentation
Quality Control for Medical Device Software - It Arena Lviv Presentation
 
Risk assessment for computer system validation
Risk assessment for computer system validationRisk assessment for computer system validation
Risk assessment for computer system validation
 
Iso 13485:2016
Iso 13485:2016Iso 13485:2016
Iso 13485:2016
 
What You Need to Know About Medical Electrical Standards Updates (and how the...
What You Need to Know About Medical Electrical Standards Updates (and how the...What You Need to Know About Medical Electrical Standards Updates (and how the...
What You Need to Know About Medical Electrical Standards Updates (and how the...
 
Human factor standards and usability (by Ed Israelski)
Human factor standards and usability (by Ed Israelski)Human factor standards and usability (by Ed Israelski)
Human factor standards and usability (by Ed Israelski)
 

Andere mochten auch

QAdvis - software risk management based on IEC/ISO 62304
QAdvis - software risk management based on IEC/ISO 62304QAdvis - software risk management based on IEC/ISO 62304
QAdvis - software risk management based on IEC/ISO 62304Robert Ginsberg
 
Death by documentation - Medical Device Development Challenges
Death by documentation - Medical Device Development ChallengesDeath by documentation - Medical Device Development Challenges
Death by documentation - Medical Device Development ChallengesAligned AG
 
ISO 14971 Risk Management - how others do it
ISO 14971 Risk Management - how others do itISO 14971 Risk Management - how others do it
ISO 14971 Risk Management - how others do itAligned AG
 
Create Your Company Page
Create Your Company PageCreate Your Company Page
Create Your Company PageTariq Ahmad
 
Abbott overview medical device human factors standards
Abbott overview medical device human factors standardsAbbott overview medical device human factors standards
Abbott overview medical device human factors standardsJones Wu
 
Beyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability Matrix
Beyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability MatrixBeyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability Matrix
Beyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability MatrixSeapine Software
 
Product Safety Testing Reduces the Risk of Shock, Fire, Explosions
Product Safety Testing Reduces the Risk of Shock, Fire, ExplosionsProduct Safety Testing Reduces the Risk of Shock, Fire, Explosions
Product Safety Testing Reduces the Risk of Shock, Fire, ExplosionsSam Davis
 
Death to project documentation with eXtreme Programming
Death to project documentation with eXtreme ProgrammingDeath to project documentation with eXtreme Programming
Death to project documentation with eXtreme ProgrammingAlex Fernandez
 
TÜV SÜD on functional safety for multi-core architectures
TÜV SÜD on functional safety for multi-core architecturesTÜV SÜD on functional safety for multi-core architectures
TÜV SÜD on functional safety for multi-core architecturesTorben Haagh
 
ZMPCZM016000.13.03 Certificate of compliance
ZMPCZM016000.13.03 Certificate of complianceZMPCZM016000.13.03 Certificate of compliance
ZMPCZM016000.13.03 Certificate of compliancepainezeeman
 
Building your credibility with LinkedIn
Building your credibility with LinkedInBuilding your credibility with LinkedIn
Building your credibility with LinkedInTariq Ahmad
 
Home Healthcare, IEC 60601-1-11
Home Healthcare, IEC 60601-1-11Home Healthcare, IEC 60601-1-11
Home Healthcare, IEC 60601-1-11Intertek
 
What Is SEO? A Guide to Search Engine Optimization
What Is SEO? A Guide to Search Engine OptimizationWhat Is SEO? A Guide to Search Engine Optimization
What Is SEO? A Guide to Search Engine OptimizationWill Marlow Agency
 
Image segmentation ppt
Image segmentation pptImage segmentation ppt
Image segmentation pptGichelle Amon
 
Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?
Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?
Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?Ana Hoffman
 
The 7 Biggest Trends in SEO: 2016
The 7 Biggest Trends in SEO: 2016The 7 Biggest Trends in SEO: 2016
The 7 Biggest Trends in SEO: 2016Rand Fishkin
 

Andere mochten auch (19)

QAdvis - software risk management based on IEC/ISO 62304
QAdvis - software risk management based on IEC/ISO 62304QAdvis - software risk management based on IEC/ISO 62304
QAdvis - software risk management based on IEC/ISO 62304
 
Death by documentation - Medical Device Development Challenges
Death by documentation - Medical Device Development ChallengesDeath by documentation - Medical Device Development Challenges
Death by documentation - Medical Device Development Challenges
 
ISO 62304 & TIR 45
ISO 62304 & TIR 45ISO 62304 & TIR 45
ISO 62304 & TIR 45
 
ISO 14971 Risk Management - how others do it
ISO 14971 Risk Management - how others do itISO 14971 Risk Management - how others do it
ISO 14971 Risk Management - how others do it
 
Create Your Company Page
Create Your Company PageCreate Your Company Page
Create Your Company Page
 
Build Features, Not Apps
Build Features, Not AppsBuild Features, Not Apps
Build Features, Not Apps
 
Abbott overview medical device human factors standards
Abbott overview medical device human factors standardsAbbott overview medical device human factors standards
Abbott overview medical device human factors standards
 
Beyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability Matrix
Beyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability MatrixBeyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability Matrix
Beyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability Matrix
 
Product Safety Testing Reduces the Risk of Shock, Fire, Explosions
Product Safety Testing Reduces the Risk of Shock, Fire, ExplosionsProduct Safety Testing Reduces the Risk of Shock, Fire, Explosions
Product Safety Testing Reduces the Risk of Shock, Fire, Explosions
 
Death to project documentation with eXtreme Programming
Death to project documentation with eXtreme ProgrammingDeath to project documentation with eXtreme Programming
Death to project documentation with eXtreme Programming
 
TÜV SÜD on functional safety for multi-core architectures
TÜV SÜD on functional safety for multi-core architecturesTÜV SÜD on functional safety for multi-core architectures
TÜV SÜD on functional safety for multi-core architectures
 
ZMPCZM016000.13.03 Certificate of compliance
ZMPCZM016000.13.03 Certificate of complianceZMPCZM016000.13.03 Certificate of compliance
ZMPCZM016000.13.03 Certificate of compliance
 
Building your credibility with LinkedIn
Building your credibility with LinkedInBuilding your credibility with LinkedIn
Building your credibility with LinkedIn
 
Home Healthcare, IEC 60601-1-11
Home Healthcare, IEC 60601-1-11Home Healthcare, IEC 60601-1-11
Home Healthcare, IEC 60601-1-11
 
What Is SEO? A Guide to Search Engine Optimization
What Is SEO? A Guide to Search Engine OptimizationWhat Is SEO? A Guide to Search Engine Optimization
What Is SEO? A Guide to Search Engine Optimization
 
IMAGE SEGMENTATION.
IMAGE SEGMENTATION.IMAGE SEGMENTATION.
IMAGE SEGMENTATION.
 
Image segmentation ppt
Image segmentation pptImage segmentation ppt
Image segmentation ppt
 
Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?
Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?
Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?
 
The 7 Biggest Trends in SEO: 2016
The 7 Biggest Trends in SEO: 2016The 7 Biggest Trends in SEO: 2016
The 7 Biggest Trends in SEO: 2016
 

Ähnlich wie Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM

Concepts in Software Safety
Concepts in Software SafetyConcepts in Software Safety
Concepts in Software Safetydalesanders
 
Online Training Information Security Management
Online Training Information Security ManagementOnline Training Information Security Management
Online Training Information Security Managementeasy2comply
 
Elements to Consider for Risk Assessment in SaMDs
Elements to Consider for Risk Assessment in SaMDsElements to Consider for Risk Assessment in SaMDs
Elements to Consider for Risk Assessment in SaMDsEMMAIntl
 
Hazard assessment and risk management techniques
Hazard assessment and risk management techniquesHazard assessment and risk management techniques
Hazard assessment and risk management techniquesPRANJAY PATIL
 
Risk management in development of life critical systems
Risk management in development of life critical systemsRisk management in development of life critical systems
Risk management in development of life critical systemsScott Althouse
 
risk-management-121021125051-phpapp02 (1).pdf
risk-management-121021125051-phpapp02 (1).pdfrisk-management-121021125051-phpapp02 (1).pdf
risk-management-121021125051-phpapp02 (1).pdfPriyanshTan
 
Critical Steps in Software Development: Enhance Your Chances for a Successful...
Critical Steps in Software Development: Enhance Your Chances for a Successful...Critical Steps in Software Development: Enhance Your Chances for a Successful...
Critical Steps in Software Development: Enhance Your Chances for a Successful...Sterling Medical Devices
 
Risk Assessment
Risk AssessmentRisk Assessment
Risk Assessmentanandeee88
 
Application Threat Modeling
Application Threat ModelingApplication Threat Modeling
Application Threat ModelingMarco Morana
 
An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...
An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...
An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...Yoshio SAKAI
 
Risk management(software engineering)
Risk management(software engineering)Risk management(software engineering)
Risk management(software engineering)Priya Tomar
 
Software Security Initiatives
Software Security InitiativesSoftware Security Initiatives
Software Security InitiativesMarco Morana
 
Risk-management
 Risk-management Risk-management
Risk-managementUmesh Gupta
 
Risk Assessment Model and its Integration into an Established Test Process
Risk Assessment Model and its Integration into an Established Test ProcessRisk Assessment Model and its Integration into an Established Test Process
Risk Assessment Model and its Integration into an Established Test Processijtsrd
 
06 overview of_ra1
06 overview of_ra106 overview of_ra1
06 overview of_ra1Anil Raina
 
Software testing-and-risk-analysis
Software testing-and-risk-analysisSoftware testing-and-risk-analysis
Software testing-and-risk-analysisAjit Waje
 

Ähnlich wie Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM (20)

Concepts in Software Safety
Concepts in Software SafetyConcepts in Software Safety
Concepts in Software Safety
 
Online Training Information Security Management
Online Training Information Security ManagementOnline Training Information Security Management
Online Training Information Security Management
 
Elements to Consider for Risk Assessment in SaMDs
Elements to Consider for Risk Assessment in SaMDsElements to Consider for Risk Assessment in SaMDs
Elements to Consider for Risk Assessment in SaMDs
 
Hazard assessment and risk management techniques
Hazard assessment and risk management techniquesHazard assessment and risk management techniques
Hazard assessment and risk management techniques
 
Risk management in development of life critical systems
Risk management in development of life critical systemsRisk management in development of life critical systems
Risk management in development of life critical systems
 
Security assessment isaca sv presentation jan 2016
Security assessment isaca sv presentation jan 2016Security assessment isaca sv presentation jan 2016
Security assessment isaca sv presentation jan 2016
 
risk-management-121021125051-phpapp02 (1).pdf
risk-management-121021125051-phpapp02 (1).pdfrisk-management-121021125051-phpapp02 (1).pdf
risk-management-121021125051-phpapp02 (1).pdf
 
Critical Steps in Software Development: Enhance Your Chances for a Successful...
Critical Steps in Software Development: Enhance Your Chances for a Successful...Critical Steps in Software Development: Enhance Your Chances for a Successful...
Critical Steps in Software Development: Enhance Your Chances for a Successful...
 
Unit 7
Unit 7Unit 7
Unit 7
 
Risk Assessment
Risk AssessmentRisk Assessment
Risk Assessment
 
Application Threat Modeling
Application Threat ModelingApplication Threat Modeling
Application Threat Modeling
 
MBA_Project_Presentation
MBA_Project_PresentationMBA_Project_Presentation
MBA_Project_Presentation
 
Ch9
Ch9Ch9
Ch9
 
An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...
An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...
An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...
 
Risk management(software engineering)
Risk management(software engineering)Risk management(software engineering)
Risk management(software engineering)
 
Software Security Initiatives
Software Security InitiativesSoftware Security Initiatives
Software Security Initiatives
 
Risk-management
 Risk-management Risk-management
Risk-management
 
Risk Assessment Model and its Integration into an Established Test Process
Risk Assessment Model and its Integration into an Established Test ProcessRisk Assessment Model and its Integration into an Established Test Process
Risk Assessment Model and its Integration into an Established Test Process
 
06 overview of_ra1
06 overview of_ra106 overview of_ra1
06 overview of_ra1
 
Software testing-and-risk-analysis
Software testing-and-risk-analysisSoftware testing-and-risk-analysis
Software testing-and-risk-analysis
 

Kürzlich hochgeladen

Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...FIDO Alliance
 
Generative AI Use Cases and Applications.pdf
Generative AI Use Cases and Applications.pdfGenerative AI Use Cases and Applications.pdf
Generative AI Use Cases and Applications.pdfalexjohnson7307
 
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdfIntroduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdfFIDO Alliance
 
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfWhere to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfFIDO Alliance
 
2024 May Patch Tuesday
2024 May Patch Tuesday2024 May Patch Tuesday
2024 May Patch TuesdayIvanti
 
TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024Stephen Perrenod
 
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...panagenda
 
Design and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data ScienceDesign and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data SciencePaolo Missier
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfFIDO Alliance
 
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...ScyllaDB
 
The Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and InsightThe Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and InsightSafe Software
 
Vector Search @ sw2con for slideshare.pptx
Vector Search @ sw2con for slideshare.pptxVector Search @ sw2con for slideshare.pptx
Vector Search @ sw2con for slideshare.pptxjbellis
 
How we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdfHow we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdfSrushith Repakula
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...FIDO Alliance
 
Using IESVE for Room Loads Analysis - UK & Ireland
Using IESVE for Room Loads Analysis - UK & IrelandUsing IESVE for Room Loads Analysis - UK & Ireland
Using IESVE for Room Loads Analysis - UK & IrelandIES VE
 
Intro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераIntro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераMark Opanasiuk
 
AI mind or machine power point presentation
AI mind or machine power point presentationAI mind or machine power point presentation
AI mind or machine power point presentationyogeshlabana357357
 
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdfMuhammad Subhan
 
Tales from a Passkey Provider Progress from Awareness to Implementation.pptx
Tales from a Passkey Provider  Progress from Awareness to Implementation.pptxTales from a Passkey Provider  Progress from Awareness to Implementation.pptx
Tales from a Passkey Provider Progress from Awareness to Implementation.pptxFIDO Alliance
 
Continuing Bonds Through AI: A Hermeneutic Reflection on Thanabots
Continuing Bonds Through AI: A Hermeneutic Reflection on ThanabotsContinuing Bonds Through AI: A Hermeneutic Reflection on Thanabots
Continuing Bonds Through AI: A Hermeneutic Reflection on ThanabotsLeah Henrickson
 

Kürzlich hochgeladen (20)

Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...
 
Generative AI Use Cases and Applications.pdf
Generative AI Use Cases and Applications.pdfGenerative AI Use Cases and Applications.pdf
Generative AI Use Cases and Applications.pdf
 
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdfIntroduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
 
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfWhere to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
 
2024 May Patch Tuesday
2024 May Patch Tuesday2024 May Patch Tuesday
2024 May Patch Tuesday
 
TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024
 
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
 
Design and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data ScienceDesign and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data Science
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
 
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
 
The Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and InsightThe Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and Insight
 
Vector Search @ sw2con for slideshare.pptx
Vector Search @ sw2con for slideshare.pptxVector Search @ sw2con for slideshare.pptx
Vector Search @ sw2con for slideshare.pptx
 
How we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdfHow we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdf
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
 
Using IESVE for Room Loads Analysis - UK & Ireland
Using IESVE for Room Loads Analysis - UK & IrelandUsing IESVE for Room Loads Analysis - UK & Ireland
Using IESVE for Room Loads Analysis - UK & Ireland
 
Intro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераIntro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджера
 
AI mind or machine power point presentation
AI mind or machine power point presentationAI mind or machine power point presentation
AI mind or machine power point presentation
 
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf
 
Tales from a Passkey Provider Progress from Awareness to Implementation.pptx
Tales from a Passkey Provider  Progress from Awareness to Implementation.pptxTales from a Passkey Provider  Progress from Awareness to Implementation.pptx
Tales from a Passkey Provider Progress from Awareness to Implementation.pptx
 
Continuing Bonds Through AI: A Hermeneutic Reflection on Thanabots
Continuing Bonds Through AI: A Hermeneutic Reflection on ThanabotsContinuing Bonds Through AI: A Hermeneutic Reflection on Thanabots
Continuing Bonds Through AI: A Hermeneutic Reflection on Thanabots
 

Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM

  • 1. Risk Management and IEC 62304 Applying IEC 62304 Risk Management in Aligned Elements February 2015
  • 2. Elements Medical Devices and Risk Management  Workflows and functions drives Risk Management  Risk Management drives Design  Design and Risk Management are interdependent  Traceability connects Design and Risk Management Workflows & Functions Hazardous Situation Risk Risk Control Design
  • 3. Elements Risk Management and Regulations ISO 13485 QMS ISO 14971 Risk Management IEC 62304 Software Lifecycle IEC 60601-1 Security in Electromedical devices IEC 62366 Usability Refers to Refers to Refers to
  • 4. Elements Risk Management and Regulations ISO 13485 QMS ISO 14971 Risk Management IEC 62304 Software Lifecycle Design & Maintenance of software in MD IEC 60601-1 Security in Electromedical devices IEC 62366 Usability Affects Affects Affects
  • 5. Elements General Concepts of Risk Assessments  Identify Hazards  Evaluate Risks (likelihood & consequences)  Perform Risk Reduction  Evaluate residual Risks
  • 6. Elements Risk Management in IEC 62304  Risk drives the level of documentation required  Software Safety Classification of architectural artifacts  Risk inheritance in architecture  Systematic risks => 100% probability of occurrence  Affects not only development, also affects maintenance Software System Class C Software Item Class C Software Unit Class C Software Unit Class B Software Item Class A Software Item Class A
  • 7. Elements Documenting Medical Device Development  Increasing number of regulations  Development documentation is difficult, complex and resource intensive to manage  Aligned Elements helps you “build” a consistent and complete documentation  Free up valuable resources from cumbersome administrative tasks
  • 8. Elements Aligned Elements – a medical device ALM  Manages the DHF Design Control Items  Version Control + Traceability + Documents  Integrated Risk Management  Real-time quality checks on content  Ensures completeness and consistency
  • 9. Elements FMEA  Concerns Safety & “Business”  Widely adopted technique  Versatile usage  Probability x Severity x Visibility Preliminary Hazard Analysis  Concerns Safety / Harm only  In the early design phase  Full device implementation is not required  Aligned with ISO 14971 Risk Assessments in Aligned Elements
  • 10. Elements Preliminary Hazard Analysis (PHA) Overview Cause (with probability) Harm (with severity) Hazardous Situation Risk Control Measure Hazard
  • 11. Elements Risk Analysis Element PHA in Aligned Elements Cause Harm (with severity) Hazardous Situation Risk Control Measure Reusable Elements Probability of Harm Potential Hazard
  • 14. Elements Risk Analysis PHA and Traceability Cause 1 Measure 1 Cause 2 Cause 3 Measure 2 Measure 3 SW Use Case HW Function SW Item SW Requirement Instructions For Use HW Specification Potential Hazards
  • 15. Elements Aligned Elements as Risk Management Tool  Automatic calculation of RPN  Automatic checks of RPN against thresholds  Reuse of Harms, Causes and Measures  Measures grouped and sorted according to Risk Reduction Type  Highlighting of insufficiently controlled risks  Highlighting of unimplemented Measures  Risk elements integrated with Design trace landscape
  • 16. Elements Risk Management in IEC 62304 Cause Hazardous Situation Risk Reduction Measure Hazard Software Item Software Requirement Verification IEC 62304 – 7.3.3 Document Traceability
  • 17. Elements Risk Analysis IEC 62304 PHA in Aligned Elements Cause Measure Software Item (with classification) SW Requirement Verification Harm Does classification match Harms in the Risk Analysis? Hazardous Situation Are Risk Control Measures implemented and verified?
  • 18. Elements Software Safety Classification (SSC) in Aligned Automatic Rule Checks:  Is SSC consistent with severity of (implicitly) linked Harms?  Is SSC consistent with classification of dependent Software Items? Specify Rules:  SSC inheritance of Software Items  Software Item must trace to Cause  Connect Severity of Harm with SSC Severity of Harm Classification 5 or 4 C 3 or 2 B 1 A
  • 19. Elements Risk Analysis SSC example in Aligned Elements Cause Software Item (Class B) SW Unit (Class C) Harm Severity: 5 Not OK! Not OK! Severity of Harm Classification 5 or 4 C 3 or 2 B 1 A
  • 20. Elements IEC 62304 and Probability in Risk Management  Software error probability is difficult to estimate  Software errors are systematic  IEC 62304 claims that Software Safety Classification shall not depend on probability, only on harm  Assume Probability of software error = 100% (section 4.3. a)  Can we reduce the probability with our Risk Control Measures?
  • 21. Elements Use two probabilities:  Probability of Hazardous Situation (P1)  Probability of Harm (P2) Usage:  P2 can be estimated by professional (e.g. a Medical Doctor)  Adapt risk policy and thresholds  Risk Control Measures affect P1 and P2 Using two probabilities Software Error Hazardous Situation Harm P1 P2
  • 22. Elements Two probabilities in Aligned Elements
  • 23. Elements Two probabilities in Aligned Elements
  • 24. Elements Architecture vs. Functional Usage  Architecture: Hierarchical decomposition of Software into Items and Units  Software risk emanates from how we use the software i.e. in which functional context we use the software items  Functional use cuts across the architecture Use Case 1 (high risk) Use Case 2 (mid risk) Use Case 3 (low risk) SW Item 1 SW Item 2 SW Item 4 SW Item 3 SW Unit 1 SW Unit 2 SW Unit 3
  • 26. Elements Matrix Model in Aligned Elements  Write Use Cases from SW Reqs  Perform Risk Analysis on Use Cases  Generate Causes from Use Cases where applicable  Create Architecture  Map Use Cases to Software Items by connecting Software Items to existing Causes  If applicable, generate new Causes from Software Items and map back to User CasesRisk Analysis Causes Software Requirements Harm Hazardous Situation Software Items
  • 27. Elements Software Problem Resolution Process  Record Problem Report  Identify Causes and perform risk analysis  Evaluate Risk  Create Change Request (if applicable)  Verify Change Risk AnalysisCause Measure Problem Report Change Request Verification Harm Hazardous Situation
  • 28. Elements Aligned Elements IEC 62304 Package  Full template set for all IEC 62304 Artifacts  Includes clear references to applicable sections in IEC 62304  Full usage of Aligned Elements automatic consistency checks  Integrated Checklists and Review Generators  Preconfigured Word reports  Preconfigured Trace Tables  Preconfigured Queries
  • 30. Thank You!Aligned AG Binzmühlstrasse 210 CH-8050 Zürich Switzerland t +41 (0)44 312 50 20 f +41 (0)44 312 50 20 m info@aligned.ch w www.aligned.ch