Contains Nonbinding Recommendations 
 
 
 
 25 
(d) 
Security Use Case Views 
In addition to the views identified above, security use case views should also be provided. 
Security use cases should be included for all medical device system functionality through which 
a security compromise could impact the safety or effectiveness of the device. These security use 
cases should cover various operational states of elements in the medical device system (e.g., 
power on, standby, transition states) and assess clinical functionality states of the medical device 
system (e.g., programming, alarming, delivering therapy, send/receive data, reporting diagnostic 
results).  
 
The number of security use cases that should be assessed will scale with the cybersecurity 
complexity and risk of the device. Each view should include detailed information as 
recommended in Appendix 2. For use cases identified that share the same security assessment, 
the associated diagrams and explanatory text can describe the multiple use cases covered by the 
view in lieu of providing duplicative information in multiple places. For example, programming 
commands and sending/receiving device data may share the same communication protocol and 
therefore may not exhibit differences between the security views for both scenarios, despite 
having different clinical risk assessments. 
 
C. 
Cybersecurity Testing 
As with other areas of product development, testing is used to demonstrate the effectiveness of 
design controls. While software development and cybersecurity are closely related disciplines, 
cybersecurity controls require testing beyond standard software verification and validation 
activities to demonstrate the effectiveness of the controls in a proper security context to therefore 
demonstrate that the device has a reasonable assurance of safety and effectiveness.  
 
Under 21 CFR 820.30(f), a manufacturer must establish and maintain procedures for verifying 
the device design. Such verification shall confirm that the design output meets the design input 
requirements. Under 21 CFR 820.30(g), a manufacturer must establish and maintain procedures 
for validating its device design. Such design validation shall include software validation and risk 
analysis, where appropriate. FDA recommends verification and validation include sufficient 
testing performed by the manufacturer on the cybersecurity of the medical device system through 
which the manufacturer verifies and validates their inputs and outputs, as appropriate.  
 
Security testing documentation and any associated reports or assessments should be submitted in 
the premarket submission. FDA recommends that the following types of testing, among others, 
be considered for inclusion in the submission: 
 
• Security requirements; 
• Manufacturers should provide evidence that each design input requirement was 
implemented successfully. 
• Manufacturers should provide evidence of their boundary analysis and rationale 
for their boundary assumptions. 
• Threat mitigation; 
• Manufacturers should provide details and evidence of testing that demonstrates 
effective risk control measures according to the threat models provided in the 
