Here’s our next example of an Additional Information Request:
FDA Additional Information Request - Example #23: Missing Cybersecurity Risk Documentation
a. Does not summarize the outcome and your assessment of the following documentation elements:
- Software Bill of Materials (SBOM)
- Component support information
- Vulnerability assessment(s)
- Unresolved anomaly assessment(s)
b. Does not:
- Summarize the risk evaluation methods and processes
- Detail the residual risk conclusion from the security risk assessment
- Detail the risk mitigation activities undertaken as part of your risk management processes
- Provide traceability between the threat model, cybersecurity risk assessment, SBOM, and testing documentation as well as other relevant cybersecurity risk management documentation
An adequate cybersecurity risk management report is important to comply with the requirement specified in section 524B(b)(2) of the Federal Food, Drug, and Cosmetic Act to provide a reasonable assurance that the device and related systems are cybersecure. It is also consistent with the recommendations in Section V.A of the FDA guidance “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions” (https://www.fda.gov/media/119933/download).
Therefore, please update your cybersecurity risk management report and any other affected documentation to address these concerns.
Please update your cybersecurity risk management report and any other affected documentation to address these concerns.
- Software Bill of Materials (SBOM)
- Component support information
- Vulnerability assessment(s)
- Unresolved anomaly assessment(s)
- Summarize the risk evaluation methods and processes
- Detail the residual risk conclusion from the security risk assessment
- Detail the risk mitigation activities undertaken as part of your risk management processes
- Provide traceability between the threat model, cybersecurity risk assessment, SBOM, and testing documentation as well as other relevant cybersecurity risk management documentation.
In this example, the FDA expressed its concerns specifically about the cybersecurity risk management report and missing relevant content. However, the manufacturer failed to submit documentation related to the proper development, verification, and documentation of the underlying cybersecurity activities (8 bullet points) raised by the FDA. The lack of this information apparently left the cybersecurity risk management report lacking details.
These 8 cybersecurity activities comprise almost all of the product’s cybersecurity development effort. Effectively, the FDA is requiring the manufacturer to go back and perform these activities. The results need to include thorough cybersecurity documentation, which supports tracing from security architecture views, through threat models, risk assessment/control, allocation of risk controls to components, and testing to ensure proper verification of the implementation.
Once completed, the FDA wants the entire set of cybersecurity-related documentation provided as part of the manufacturer’s response to the AIR.