用标准化模型提升医疗设备网络安全文档的可审查性与一致性。
Supporting Cybersecurity Risk Management for Medical Devices via the SECUMAN Ontology and Shapes

- 构建基于OWL的SECUMAN本体,统一描述安全风险上下文与控制措施。
- 通过SHACL约束确保文档结构完整,支持自动化初步验证。
- 适合医疗器械安全合规团队及认证机构使用,提升文档可追溯性。
我们提出SECUMAN本体及形状规范,用于表示和分析医疗设备的网络安全风险管理文档。随着联网医疗设备普及,网络安全风险可能直接影响患者安全。当前风险文档多以半结构化自然语言文本形式存在,导致一致性检查、认证审核和复用困难。SECUMAN采用基于OWL的形式化词汇表,建模安全风险背景、评估、控制措施及残余风险评估,并利用SHACL约束验证文档结构完整性与模型符合性。该本体与VDE Spec 90025及RISKMAN本体对齐,同时扩展其安全导向方法,涵盖威胁场景、保护目标、攻击者画像、暴露等级、资产和安全设计论证等关键概念。旨在支持网络安全与安全风险管理文档的自动化初审、可追溯性与集成。
原文摘要 · Abstract (English)
We propose the SECUMAN ontology and shapes for representing and analysing cybersecurity risk-management documentation for medical devices. Cybersecurity risks are increasingly relevant for connected medical devices and may have direct consequences for patient safety. Current risk-management files are often maintained as semi-structured natural language text, which makes consistency checking, certification review, and reuse difficult. SECUMAN provides a formal OWL-based vocabulary for modelling security-risk context, assessment, control measures, and residual-risk evaluation, and uses SHACL constraints to check structural completeness and conformity with the intended documentation model. The ontology is aligned with VDE Spec 90025 and the related RISKMAN ontology and shapes, while extending their safety-oriented approach to concepts relevant to cybersecurity risk documentation such as threat scenarios, protection goals, attacker profiles, exposure levels, assets, and secure design arguments. SECUMAN is intended to support automated first-pass validation, traceability, and integration of cybersecurity and safety risk-management documentation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。