The Atlan A350/XL anaesthesia machine was designed with security in mind to combat dangerous and damaging cyber-attacks.
We implemented measures considering the NIST security best practices framework.
- Identify:
Dedicated documents with security relev … More information
ant information are provided for asset risk management (e.g. Software Bill of Material, MDS2 Form, comprehensive cybersecurity whitepaper).Protect:A secure boot ensures the integrity of the software running on the deviceRole-based authentication & authorisation prevents unauthorised access to critical settings and dataHardened operating system by omitting all unnecessary software components and disabling all unused ports minimises attack surface Detect:Security relevant events are detected, logged in a tamper-proof security log file and IT-admin is notified via SNMP trapsRespond:The system health monitor observes the system load carefully and reacts in case of suspected malicious events, i.e., disable network interface if load is unusually highRecover:The system can reboot into last good known state if security event is detected. Dräger service can restore hard- and software quickly, clinical configuration can be transferred from other devices via USB drive Atlan was developed as to our secure development lifecycle encompassing: Threat analysis to identify vulnerabilities during the development phase Automatic code analysis along software development Independent 3rd party penetration testing to discover residual vulnerabilities Execution only of signed (trusted) code on the device Release of patches if relevant vulnerability was detected Continuous vulnerability monitoring along the lifecycle of the product