83_FR_21362 83 FR 21272 - National Cybersecurity Center of Excellence (NCCoE) Securing Picture Archiving and Communication System (PACS) Cybersecurity for the Healthcare Sector

83 FR 21272 - National Cybersecurity Center of Excellence (NCCoE) Securing Picture Archiving and Communication System (PACS) Cybersecurity for the Healthcare Sector

DEPARTMENT OF COMMERCE
National Institute of Standards and Technology

Federal Register Volume 83, Issue 90 (May 9, 2018)

Page Range21272-21274
FR Document2018-09897

The National Institute of Standards and Technology (NIST) invites organizations to provide products and technical expertise to support and demonstrate security platforms for the Securing Picture Archiving and Communication System (PACS) Cybersecurity for the healthcare sector. This notice is the initial step for the National Cybersecurity Center of Excellence (NCCoE) in collaborating with technology companies to address cybersecurity challenges identified under the healthcare sector program. Participation in the use case is open to all interested organizations.

Federal Register, Volume 83 Issue 90 (Wednesday, May 9, 2018)
[Federal Register Volume 83, Number 90 (Wednesday, May 9, 2018)]
[Notices]
[Pages 21272-21274]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2018-09897]


=======================================================================
-----------------------------------------------------------------------

DEPARTMENT OF COMMERCE

National Institute of Standards and Technology

[Docket No. 180319295-8295-01]


National Cybersecurity Center of Excellence (NCCoE) Securing 
Picture Archiving and Communication System (PACS) Cybersecurity for the 
Healthcare Sector

AGENCY: National Institute of Standards and Technology, Department of 
Commerce.

ACTION: Notice.

-----------------------------------------------------------------------

SUMMARY: The National Institute of Standards and Technology (NIST) 
invites organizations to provide products and technical expertise to 
support and demonstrate security platforms for the Securing Picture 
Archiving and Communication System (PACS) Cybersecurity for the 
healthcare sector. This notice is the initial step for the National 
Cybersecurity Center of Excellence (NCCoE) in collaborating with 
technology companies to address cybersecurity challenges identified 
under the healthcare sector program. Participation in the use case is 
open to all interested organizations.

DATES: Collaborative activities will commence as soon as enough 
completed and signed letters of interest have been returned to address 
all the necessary components and capabilities, but no earlier than June 
8, 2018.

ADDRESSES: The NCCoE is located at 9700 Great Seneca Highway, 
Rockville, MD 20850. Letters of interest must be submitted to 
[email protected] or via hardcopy to National Institute of Standards 
and Technology, NCCoE, 9700 Great Seneca Highway, Rockville, MD 20850. 
Organizations whose letters of interest are accepted in accordance with 
the process set forth in the SUPPLEMENTARY INFORMATION section of this 
notice will be asked to sign a consortium Cooperative Research and 
Development Agreement (CRADA) with NIST. An NCCoE consortium CRADA 
template can be found at: http://nccoe.nist.gov/node/138.

FOR FURTHER INFORMATION CONTACT: Andrea Arbelaez via email to 
[email protected]; by telephone 301-975-0214; or by mail to National 
Institute of Standards and Technology, NCCoE, 9700 Great Seneca 
Highway, Rockville, MD 20850. Additional details about the healthcare 
sector program are available at https://nccoe.nist.gov/projects/use-cases/health-it/pacs.

SUPPLEMENTARY INFORMATION: Interested parties must contact NIST to 
request a letter of interest template to be completed and submitted to 
NIST. Letters of interest will be accepted on a first come, first 
served basis. When the use case has been completed, NIST will post a 
notice on the NCCoE healthcare sector program website at https://nccoe.nist.gov/projects/use-cases/health-it/pacs announcing the 
completion of the use case and informing the public that it will no 
longer accept letters of interest for this use case.
    Background: The NCCoE, part of NIST, is a public-private 
collaboration for accelerating the widespread adoption of integrated 
cybersecurity tools and technologies. The NCCoE brings together experts 
from industry, government, and academia under one roof to develop 
practical, interoperable cybersecurity approaches that address the 
real-world needs of complex Information Technology (IT) systems. By 
accelerating dissemination and use of these integrated tools and 
technologies for protecting IT assets, the NCCoE will enhance trust in 
U.S. IT communications, data, and storage systems; reduce risk for 
companies and individuals using IT systems; and encourage development 
of innovative, job-creating cybersecurity products and services.
    Process: NIST is soliciting responses from all sources of relevant 
security capabilities (see below) to enter into a Cooperative Research 
and Development Agreement (CRADA) to provide products and technical 
expertise to support and demonstrate security platforms for the 
Securing Picture Archiving and Communication System (PACS) 
Cybersecurity for the healthcare sector. The full use case can be 
viewed at: https://nccoe.nist.gov/projects/use-cases/health-it/pacs.

[[Page 21273]]

    Interested parties should contact NIST using the information 
provided in the FOR FURTHER INFORMATION CONTACT section of this notice. 
NIST will then provide each interested party with a letter of interest 
template, which the party must complete, certify that it is accurate, 
and submit to NIST. NIST will contact interested parties if there are 
questions regarding the responsiveness of the letters of interest to 
the use case objective or requirements identified below. NIST will 
select participants who have submitted complete letters of interest on 
a first come, first served basis within each category of product 
components or capabilities listed below up to the number of 
participants in each category necessary to carry out this use case. 
However, there may be continuing opportunity to participate even after 
initial activity commences. Selected participants will be required to 
enter into a consortium CRADA with NIST (for reference, see ADDRESSES 
section above). NIST published a notice in the Federal Register on 
October 19, 2012 (77 FR 64314) inviting U.S. companies to enter into 
National Cybersecurity Excellence Partnerships (NCEPs) in furtherance 
of the NCCoE. For this demonstration project, NCEP partners will not be 
given priority for participation.

Use Case Objective

    To provide guidance and a referenceable architecture for securing 
the Picture Archiving and Communication System (PACS) ecosystem in 
Healthcare Delivery Organizations (HDOs), and to include an example 
solution using existing, commercially and open-source available 
cybersecurity products.
    A detailed description of the Securing Picture Archiving and 
Communication System (PACS) Cybersecurity for the healthcare sector is 
available at: https://nccoe.nist.gov/projects/use-cases/health-it/pacs.
    Requirements: Each responding organization's letter of interest 
should identify which security platform component(s) or capability(ies) 
it is offering. Letters of interest should not include company 
proprietary information, and all components and capabilities must be 
commercially available. Components are listed in section 2 of the 
Securing Picture Archiving and Communication System (PACS) 
Cybersecurity for the healthcare sector use case (for reference, please 
see the link in the PROCESS section above) and include, but are not 
limited to:

 PACS Servers, special applications (including web services), 
and workstations
 Vendor Neutral Archive (VNA)
 data storage
 modality or modality simulator
 radiology information system (RIS) or RIS simulator
 notification system
 Electronic Health Record (EHR)/Electronic Medical Record (EMR)
 load balancer
 managed service model and remote service connectivity
 certificate management
 authentication mechanism
 session management
 data encryption
 endpoint protection
    [cir] encryption
    [cir] malware/virus protection
    [cir] Host Intrusion Prevention System (HIPS)/Host Intrusion 
Detection System (HIDS)
 logging, monitoring, security information and event management 
(SIEM)
 network infrastructure controls
 asset management
 web services

    Each responding organization's letter of interest should identify 
how their products address one or more of the following desired 
security characteristics in section 2 of the Securing Picture Archiving 
and Communication System (PACS) Cybersecurity for the healthcare sector 
use case (for reference, please see the link in the PROCESS section 
above):
    The primary security functions and processes to be implemented for 
this project are listed below and are based on the NIST Cybersecurity 
Framework (CSF).

Identify (ID)

 Asset Management--includes identification of assets on network 
and management of the assets to be deployed to workstations
 Risk Assessment--includes risk management strategy

Protect (PR)

 Access Control--includes user account management, remote 
access
    [cir] controlling (and auditing) user accounts
    [cir] controlling (and auditing) access by external users
    [cir] enforcing least privilege for all (internal and external) 
users
    [cir] enforcing separation of duties policies
    [ssquf] Privileged Access Management (PAM) with an emphasis on the 
segregation of duties
    [cir] enforcing least functionality
 User Identification and Authentication
    [cir] multifactor authentication for the system that aligns with 
the sensitive information and function that PACS performs; NIST-
recommended algorithms; usability; impact on system performance; and 
raising the assurance profile, and higher NIST Special Publication (SP) 
800-63-3 levels, bring a higher level of assurance
    [cir] viable federated identity management
    [cir] credential management
 Data Security--includes data confidentiality, integrity, and 
availability
    [cir] securing and monitoring storage of data--includes data 
encryption (for data at rest)
    [ssquf] access control on data
    [ssquf] data-at-rest controls should implement some form of a data 
security manager that would allow for policy application to encrypted 
data, inclusive of access control policy
    [cir] securing the distribution of data--includes data encryption 
(for data in transit) and data loss prevention mechanism
    [cir] controls that promote data integrity
    [cir] cryptographic modules validated as meeting NIST Federal 
Information Processing Standard (FIPS) 140-2 are preferred
    [cir] physical security provided by an access controlled data 
center to host the PACS servers and storage
 Information Protection Processes and Procedures--includes data 
backup, endpoint protection for workstations
 Maintenance--local and remote maintenance
 Protective Technology--host-based intrusion prevention, 
solutions for malware (malicious code detection), audit logging, 
(automated) audit log review, and physical protection
 Communications and Network Security--communications and 
control networks are protected (e.g., firewall, network access control, 
network infrastructure controls)
    [cir] Securing and monitoring connections with the Health Delivery 
Organization (HDO) ecosystem
    [ssquf] Network segmentation
    [cir] Securing and monitoring connections to and from external 
systems

Detect (DE)

 Anomalies and Events--analysis of detected events (from logs, 
monitoring results, SIEM)
    [cir] Centralized mechanism to capture and analyze system and 
network events

[[Page 21274]]

 Security Continuous Monitoring--monitoring for unauthorized 
personnel, devices, software, connections
    [cir] vulnerability management--includes vulnerability scanning and 
remediation
    [cir] patch management
    [cir] system configuration security settings
    [cir] user account usage (local and remote) and user behavioral 
analytics

Respond (RS)

 Response Planning--response plan executed after an event, 
mitigation of security issues

Recover (RC)

 Recovery and Restoration--recovery and restoration activities 
executed after an event
    [cir] business continuity and business resumption processes
    [ssquf] In addition to restoration capability from archival media, 
the project should consider high availability and continuity for data 
storage. Implicitly, disk arrays used for image storage should have the 
capability to implement various Redundant Array of Independent Disks 
(RAID) configurations. RAID 0, 1, 5, 6, and 1+0 should be supported. 
Disk arrays should also be made available for cold or warm restore/
failover capability. Other data storage solutions that provide the same 
(or better) reliability and durability are considered.

    Responding organizations need to understand and, in their letters 
of interest, commit to provide:
    1. Access for all participants' project teams to component 
interfaces and the organization's experts necessary to make functional 
connections among security platform components
    2. Support for development and demonstration of the Securing 
Picture Archiving and Communication System (PACS) Cybersecurity for the 
healthcare sector use case in NCCoE facilities which will be conducted 
in a manner consistent with the following standards and guidance: FIPS 
200, FIPS 201, SP 800-53 and FIPS 140-2, SP 800-30, SP 800-37, SP 800-
39, SP 800-41, SP 800-52, SP 800-57, SP 800-63-3, SP 800-66, SP 800-77, 
SP 800-95, SP 800-144, SP 800-146, SP 800-171, SP 800-181, ISO 
12052:2011 Health Informatics--Digital Imaging and Communication in 
Medicine (DICOM) including Workflow and Data Management, AAMI TIR57, 
ANSI/AAMI/IEC 80001-1:2010, IEC Technical Report 80001-2-1, IEC 
Technical Report 80001-2-2, internet Engineering Task Force Request for 
Comments 4301, Food & Drug Administration (FDA) Content of Premarket 
Submissions for Management of Cybersecurity in Medical Devices, FDA 
Postmark Management of Cybersecurity in Medical Devices, FDA Guidance 
for Industry--Cybersecurity for Networked Medical Devices Containing 
Off-the-Shelf Software, FDA Guidance for Submission of Premarket 
Notifications for Medical Image Management Devices, FDA Medical Device 
Data Systems, Medical Image Storage Devices, Medical Image 
Communications Device, Department of Health & Human Services Office for 
Civil Rights Health Insurance Portability and Accountability Act 
Security Rule Crosswalk to NIST Cybersecurity Framework, Department of 
Homeland Security Attack Surface: Healthcare and Public Sector, 
Integrating the Healthcare Enterprise Radiology Technical Framework.
    Additional details about the Securing Picture Archiving and 
Communication System (PACS) Cybersecurity for the healthcare sector use 
case are available at: https://nccoe.nist.gov/projects/use-cases/health-it/pacs.
    NIST cannot guarantee that all of the products proposed by 
respondents will be used in the demonstration. Each prospective 
participant will be expected to work collaboratively with NIST staff 
and other project participants under the terms of the consortium CRADA 
in the development of the Securing Picture Archiving and Communication 
System (PACS) Cybersecurity for the healthcare sector capability. 
Prospective participants' contribution to the collaborative effort will 
include assistance in establishing the necessary interface 
functionality, connection and set-up capabilities and procedures, 
demonstration harnesses, environmental and safety conditions for use, 
integrated platform user instructions, and demonstration plans and 
scripts necessary to demonstrate the desired capabilities. Each 
participant will train NIST personnel, as necessary, to operate its 
product in capability demonstrations to the healthcare community. 
Following successful demonstrations, NIST will publish a description of 
the security platform and its performance characteristics sufficient to 
permit other organizations to develop and deploy security platforms 
that meet the security objectives of the Securing Picture Archiving and 
Communication System (PACS) Cybersecurity for the healthcare sector use 
case. These descriptions will be public information.
    Under the terms of the consortium CRADA, NIST will support 
development of interfaces among participants' products by providing IT 
infrastructure, laboratory facilities, office facilities, collaboration 
facilities, and staff support to component composition, security 
platform documentation, and demonstration activities.
    The dates of the demonstration of the Securing Picture Archiving 
and Communication System (PACS) Cybersecurity for the healthcare sector 
capability will be announced on the NCCoE website at least two weeks in 
advance at http://nccoe.nist.gov/. The expected outcome of the 
demonstration is to improve securing picture archiving and 
communications system (PACS) cybersecurity across an entire healthcare 
sector enterprise. Participating organizations will gain from the 
knowledge that their products are interoperable with other 
participants' offerings.
    For additional information on the NCCoE governance, business 
processes, and NCCoE operational structure, visit the NCCoE website 
http://nccoe.nist.gov/.

Kevin A. Kimball,
Chief of Staff.
[FR Doc. 2018-09897 Filed 5-8-18; 8:45 am]
 BILLING CODE 3510-13-P



                                             21272                         Federal Register / Vol. 83, No. 90 / Wednesday, May 9, 2018 / Notices

                                             F. Award Administration Information                     by courier: Room 6512, 1400                           of interest are accepted in accordance
                                                1. Award Notices: FAS will notify                    Independence Ave. SW, Washington,                     with the process set forth in the
                                             each applicant in writing of the final                  DC 20250, or by phone: (202) 720–4327,                SUPPLEMENTARY INFORMATION section of
                                             disposition of its application. FAS will                or by fax: (202) 720–9361, or by e–mail:              this notice will be asked to sign a
                                             send an approval letter and project                     podadmin@fas.usda.gov.                                consortium Cooperative Research and
                                             agreement to each approved applicant.                     2. Grants Management Contact(s):                    Development Agreement (CRADA) with
                                             The approval letter and project                         Eric Bozoian, Grants Management                       NIST. An NCCoE consortium CRADA
                                             agreement will specify the terms and                    Specialist, Foreign Agricultural Service,             template can be found at: http://
                                             conditions applicable to the project,                   United States, Department of                          nccoe.nist.gov/node/138.
                                             including the levels of Cooperator                      Agriculture, Email: Eric.Bozoian@                     FOR FURTHER INFORMATION CONTACT:
                                             program funding and cost–share                          fas.usda.gov, Office: (202) 378–1054.                 Andrea Arbelaez via email to HIT_
                                             contribution requirements. All                            Signed at Washington, DC on the 26th of             NCCOE@nist.gov; by telephone 301–
                                             successful applicants for all grant and                 April, 2018.                                          975–0214; or by mail to National
                                             cooperative agreements are required to                  James Higgiston                                       Institute of Standards and Technology,
                                             comply with the Standard                                Acting Administrator, Foreign Agricultural            NCCoE, 9700 Great Seneca Highway,
                                             Administrative Terms and Conditions,                    Service, and Acting Vice President,                   Rockville, MD 20850. Additional details
                                             which are available online at: https://                 Commodity Credit Corporation.                         about the healthcare sector program are
                                             www.fas.usda.gov/grants/general_                        [FR Doc. 2018–09867 Filed 5–8–18; 8:45 am]            available at https://nccoe.nist.gov/
                                             terms_and_conditions/default.asp. The                   BILLING CODE 3410–10–P                                projects/use-cases/health-it/pacs.
                                             applicable Standard Administrative                                                                            SUPPLEMENTARY INFORMATION: Interested
                                             Terms and Conditions will be for the                                                                          parties must contact NIST to request a
                                             last year specified at that URL, unless                 DEPARTMENT OF COMMERCE                                letter of interest template to be
                                             the application is to continue an award                                                                       completed and submitted to NIST.
                                             first awarded in an earlier year. In that               National Institute of Standards and                   Letters of interest will be accepted on a
                                             event, the terms and conditions that                    Technology                                            first come, first served basis. When the
                                             apply will be those in effect for the year              [Docket No. 180319295–8295–01]                        use case has been completed, NIST will
                                             in which the award was originally made                                                                        post a notice on the NCCoE healthcare
                                             unless explicitly stated otherwise in                   National Cybersecurity Center of                      sector program website at https://
                                             subsequent mutually–agreed                              Excellence (NCCoE) Securing Picture                   nccoe.nist.gov/projects/use-cases/
                                             amendments to the award.                                Archiving and Communication System                    health-it/pacs announcing the
                                                Before accepting the award the                       (PACS) Cybersecurity for the                          completion of the use case and
                                             potential awardee should carefully read                 Healthcare Sector                                     informing the public that it will no
                                             the approval letter and program                                                                               longer accept letters of interest for this
                                             agreement for instructions on                           AGENCY: National Institute of Standards               use case.
                                             administering the grant award and the                   and Technology, Department of                            Background: The NCCoE, part of
                                             terms and conditions associated with                    Commerce.                                             NIST, is a public-private collaboration
                                             responsibilities under Federal Awards.                  ACTION: Notice.                                       for accelerating the widespread
                                             Recipients must accept all conditions in                                                                      adoption of integrated cybersecurity
                                                                                                     SUMMARY:    The National Institute of                 tools and technologies. The NCCoE
                                             this NOFA as well as any special terms
                                                                                                     Standards and Technology (NIST)                       brings together experts from industry,
                                             and conditions in the approval letter
                                                                                                     invites organizations to provide                      government, and academia under one
                                             and program agreement to receive an
                                                                                                     products and technical expertise to                   roof to develop practical, interoperable
                                             award under this program.
                                                2. Reporting: FAS requires various                   support and demonstrate security                      cybersecurity approaches that address
                                             reports and evaluations from                            platforms for the Securing Picture                    the real-world needs of complex
                                             Cooperators. Required reports include                   Archiving and Communication System                    Information Technology (IT) systems.
                                             an annual contributions report that                     (PACS) Cybersecurity for the healthcare               By accelerating dissemination and use
                                             identifies contributions made by the                    sector. This notice is the initial step for           of these integrated tools and
                                             Cooperator and the U.S. industry during                 the National Cybersecurity Center of                  technologies for protecting IT assets, the
                                             that marketing plan year. All                           Excellence (NCCoE) in collaborating                   NCCoE will enhance trust in U.S. IT
                                             Cooperators must also complete at least                 with technology companies to address                  communications, data, and storage
                                             one program evaluation each year and                    cybersecurity challenges identified                   systems; reduce risk for companies and
                                             must provide program success stories on                 under the healthcare sector program.                  individuals using IT systems; and
                                             an annual basis, or more often when                     Participation in the use case is open to              encourage development of innovative,
                                             appropriate or required by FAS. There                   all interested organizations.                         job-creating cybersecurity products and
                                             are additional reporting requirements                   DATES: Collaborative activities will                  services.
                                             for trip reports, evaluation reports, and               commence as soon as enough completed                     Process: NIST is soliciting responses
                                             research reports. Reporting                             and signed letters of interest have been              from all sources of relevant security
                                             requirements are detailed in the                        returned to address all the necessary                 capabilities (see below) to enter into a
                                             Cooperator program regulations in                       components and capabilities, but no                   Cooperative Research and Development
                                             sections 1484.53, 1484.70, and 1484.72.                 earlier than June 8, 2018.                            Agreement (CRADA) to provide
                                                                                                     ADDRESSES: The NCCoE is located at                    products and technical expertise to
                                             G. Agency Contact(s)
amozie on DSK3GDR082PROD with NOTICES




                                                                                                     9700 Great Seneca Highway, Rockville,                 support and demonstrate security
                                               1. Application Submission Contact(s)                  MD 20850. Letters of interest must be                 platforms for the Securing Picture
                                             and Program Support: For additional                     submitted to HIT_NCCOE@nist.gov or                    Archiving and Communication System
                                             information and assistance, contact the                 via hardcopy to National Institute of                 (PACS) Cybersecurity for the healthcare
                                             Program Operations Division, Office of                  Standards and Technology, NCCoE,                      sector. The full use case can be viewed
                                             Trade Programs, Foreign Agricultural                    9700 Great Seneca Highway, Rockville,                 at: https://nccoe.nist.gov/projects/use-
                                             Service, U.S. Department of Agriculture                 MD 20850. Organizations whose letters                 cases/health-it/pacs.


                                        VerDate Sep<11>2014   17:39 May 08, 2018   Jkt 244001   PO 00000   Frm 00016   Fmt 4703   Sfmt 4703   E:\FR\FM\09MYN1.SGM   09MYN1


                                                                           Federal Register / Vol. 83, No. 90 / Wednesday, May 9, 2018 / Notices                                              21273

                                               Interested parties should contact NIST                •  Vendor Neutral Archive (VNA)                             system that aligns with the sensitive
                                             using the information provided in the                   •  data storage                                             information and function that PACS
                                             FOR FURTHER INFORMATION CONTACT                         •  modality or modality simulator                           performs; NIST-recommended
                                             section of this notice. NIST will then                  •  radiology information system (RIS) or                    algorithms; usability; impact on
                                             provide each interested party with a                         RIS simulator                                          system performance; and raising the
                                             letter of interest template, which the                  • notification system                                       assurance profile, and higher NIST
                                             party must complete, certify that it is                 • Electronic Health Record (EHR)/                           Special Publication (SP) 800–63–3
                                             accurate, and submit to NIST. NIST will                      Electronic Medical Record (EMR)                        levels, bring a higher level of
                                             contact interested parties if there are                 • load balancer                                             assurance
                                             questions regarding the responsiveness                  • managed service model and remote                        Æ viable federated identity
                                             of the letters of interest to the use case                   service connectivity                                   management
                                             objective or requirements identified                    • certificate management                                  Æ credential management
                                             below. NIST will select participants                    • authentication mechanism                            •   Data Security—includes data
                                             who have submitted complete letters of                  • session management                                        confidentiality, integrity, and
                                             interest on a first come, first served                  • data encryption                                           availability
                                             basis within each category of product                   • endpoint protection                                     Æ securing and monitoring storage of
                                             components or capabilities listed below                    Æ encryption                                             data—includes data encryption (for
                                             up to the number of participants in each                   Æ malware/virus protection                               data at rest)
                                             category necessary to carry out this use                   Æ Host Intrusion Prevention System                     D access control on data
                                             case. However, there may be continuing                       (HIPS)/Host Intrusion Detection                      D data-at-rest controls should
                                             opportunity to participate even after                        System (HIDS)                                          implement some form of a data
                                             initial activity commences. Selected                    • logging, monitoring, security                             security manager that would allow
                                             participants will be required to enter                       information and event management                       for policy application to encrypted
                                             into a consortium CRADA with NIST                            (SIEM)                                                 data, inclusive of access control
                                             (for reference, see ADDRESSES section                   • network infrastructure controls                           policy
                                             above). NIST published a notice in the                  • asset management                                        Æ securing the distribution of data—
                                             Federal Register on October 19, 2012                    • web services                                              includes data encryption (for data
                                             (77 FR 64314) inviting U.S. companies                      Each responding organization’s letter                    in transit) and data loss prevention
                                             to enter into National Cybersecurity                    of interest should identify how their                       mechanism
                                             Excellence Partnerships (NCEPs) in                      products address one or more of the                       Æ controls that promote data integrity
                                             furtherance of the NCCoE. For this                      following desired security                                Æ cryptographic modules validated as
                                             demonstration project, NCEP partners                    characteristics in section 2 of the                         meeting NIST Federal Information
                                             will not be given priority for                          Securing Picture Archiving and                              Processing Standard (FIPS) 140–2
                                             participation.                                          Communication System (PACS)                                 are preferred
                                                                                                     Cybersecurity for the healthcare sector                   Æ physical security provided by an
                                             Use Case Objective
                                                                                                     use case (for reference, please see the                     access controlled data center to host
                                               To provide guidance and a                             link in the PROCESS section above):                         the PACS servers and storage
                                             referenceable architecture for securing                    The primary security functions and                 •   Information Protection Processes and
                                             the Picture Archiving and                               processes to be implemented for this                        Procedures—includes data backup,
                                             Communication System (PACS)                             project are listed below and are based                      endpoint protection for
                                             ecosystem in Healthcare Delivery                        on the NIST Cybersecurity Framework                         workstations
                                             Organizations (HDOs), and to include an                 (CSF).                                                •   Maintenance—local and remote
                                             example solution using existing,                                                                                    maintenance
                                             commercially and open-source available                  Identify (ID)                                         •   Protective Technology—host-based
                                             cybersecurity products.                                 • Asset Management—includes                                 intrusion prevention, solutions for
                                               A detailed description of the Securing                    identification of assets on network                     malware (malicious code detection),
                                             Picture Archiving and Communication                         and management of the assets to be                      audit logging, (automated) audit log
                                             System (PACS) Cybersecurity for the                         deployed to workstations                                review, and physical protection
                                             healthcare sector is available at: https://             • Risk Assessment—includes risk                       •   Communications and Network
                                             nccoe.nist.gov/projects/use-cases/                          management strategy                                     Security—communications and
                                             health-it/pacs.                                                                                                     control networks are protected (e.g.,
                                               Requirements: Each responding                         Protect (PR)
                                                                                                                                                                 firewall, network access control,
                                             organization’s letter of interest should                • Access Control—includes user                              network infrastructure controls)
                                             identify which security platform                            account management, remote access                     Æ Securing and monitoring
                                             component(s) or capability(ies) it is                     Æ controlling (and auditing) user                         connections with the Health
                                             offering. Letters of interest should not                    accounts                                                Delivery Organization (HDO)
                                             include company proprietary                               Æ controlling (and auditing) access by                    ecosystem
                                             information, and all components and                         external users                                        D Network segmentation
                                             capabilities must be commercially                         Æ enforcing least privilege for all                     Æ Securing and monitoring
                                             available. Components are listed in                         (internal and external) users                           connections to and from external
                                             section 2 of the Securing Picture                         Æ enforcing separation of duties                          systems
                                             Archiving and Communication System                          policies
amozie on DSK3GDR082PROD with NOTICES




                                             (PACS) Cybersecurity for the healthcare                   D Privileged Access Management                      Detect (DE)
                                             sector use case (for reference, please see                  (PAM) with an emphasis on the                     • Anomalies and Events—analysis of
                                             the link in the PROCESS section above)                      segregation of duties                                 detected events (from logs,
                                             and include, but are not limited to:                      Æ enforcing least functionality                         monitoring results, SIEM)
                                             • PACS Servers, special applications                    • User Identification and                               Æ Centralized mechanism to capture
                                                  (including web services), and                          Authentication                                        and analyze system and network
                                                  workstations                                         Æ multifactor authentication for the                    events


                                        VerDate Sep<11>2014   17:39 May 08, 2018   Jkt 244001   PO 00000   Frm 00017   Fmt 4703   Sfmt 4703   E:\FR\FM\09MYN1.SGM   09MYN1


                                             21274                         Federal Register / Vol. 83, No. 90 / Wednesday, May 9, 2018 / Notices

                                             • Security Continuous Monitoring—                       Engineering Task Force Request for                    development of interfaces among
                                                 monitoring for unauthorized                         Comments 4301, Food & Drug                            participants’ products by providing IT
                                                 personnel, devices, software,                       Administration (FDA) Content of                       infrastructure, laboratory facilities,
                                                 connections                                         Premarket Submissions for Management                  office facilities, collaboration facilities,
                                               Æ vulnerability management—                           of Cybersecurity in Medical Devices,                  and staff support to component
                                                 includes vulnerability scanning and                 FDA Postmark Management of                            composition, security platform
                                                 remediation                                         Cybersecurity in Medical Devices, FDA                 documentation, and demonstration
                                               Æ patch management                                    Guidance for Industry—Cybersecurity                   activities.
                                               Æ system configuration security                       for Networked Medical Devices                            The dates of the demonstration of the
                                                 settings                                            Containing Off-the-Shelf Software, FDA                Securing Picture Archiving and
                                               Æ user account usage (local and                       Guidance for Submission of Premarket                  Communication System (PACS)
                                                 remote) and user behavioral                         Notifications for Medical Image                       Cybersecurity for the healthcare sector
                                                 analytics                                           Management Devices, FDA Medical                       capability will be announced on the
                                             Respond (RS)                                            Device Data Systems, Medical Image                    NCCoE website at least two weeks in
                                                                                                     Storage Devices, Medical Image                        advance at http://nccoe.nist.gov/. The
                                             • Response Planning—response plan                       Communications Device, Department of                  expected outcome of the demonstration
                                                 executed after an event, mitigation                 Health & Human Services Office for                    is to improve securing picture archiving
                                                 of security issues                                  Civil Rights Health Insurance Portability             and communications system (PACS)
                                             Recover (RC)                                            and Accountability Act Security Rule                  cybersecurity across an entire healthcare
                                                                                                     Crosswalk to NIST Cybersecurity                       sector enterprise. Participating
                                             • Recovery and Restoration—recovery                     Framework, Department of Homeland
                                                  and restoration activities executed                                                                      organizations will gain from the
                                                                                                     Security Attack Surface: Healthcare and               knowledge that their products are
                                                  after an event                                     Public Sector, Integrating the Healthcare
                                               Æ business continuity and business                                                                          interoperable with other participants’
                                                                                                     Enterprise Radiology Technical                        offerings.
                                                  resumption processes
                                                                                                     Framework.                                               For additional information on the
                                               D In addition to restoration capability
                                                                                                        Additional details about the Securing              NCCoE governance, business processes,
                                                  from archival media, the project
                                                                                                     Picture Archiving and Communication                   and NCCoE operational structure, visit
                                                  should consider high availability                  System (PACS) Cybersecurity for the
                                                  and continuity for data storage.                                                                         the NCCoE website http://
                                                                                                     healthcare sector use case are available              nccoe.nist.gov/.
                                                  Implicitly, disk arrays used for                   at: https://nccoe.nist.gov/projects/use-
                                                  image storage should have the                      cases/health-it/pacs.                                 Kevin A. Kimball,
                                                  capability to implement various                       NIST cannot guarantee that all of the              Chief of Staff.
                                                  Redundant Array of Independent                     products proposed by respondents will                 [FR Doc. 2018–09897 Filed 5–8–18; 8:45 am]
                                                  Disks (RAID) configurations. RAID                  be used in the demonstration. Each                    BILLING CODE 3510–13–P
                                                  0, 1, 5, 6, and 1+0 should be                      prospective participant will be expected
                                                  supported. Disk arrays should also                 to work collaboratively with NIST staff
                                                  be made available for cold or warm                 and other project participants under the              DEPARTMENT OF COMMERCE
                                                  restore/failover capability. Other                 terms of the consortium CRADA in the
                                                  data storage solutions that provide                development of the Securing Picture                   National Oceanic and Atmospheric
                                                  the same (or better) reliability and               Archiving and Communication System                    Administration
                                                  durability are considered.                         (PACS) Cybersecurity for the healthcare
                                               Responding organizations need to                      sector capability. Prospective                        Proposed Information Collection;
                                             understand and, in their letters of                     participants’ contribution to the                     Comment Request; Observer
                                             interest, commit to provide:                            collaborative effort will include                     Programs’ Information That Can Be
                                               1. Access for all participants’ project               assistance in establishing the necessary              Gathered Only Through Questions
                                             teams to component interfaces and the                   interface functionality, connection and
                                             organization’s experts necessary to make                                                                      AGENCY: National Oceanic and
                                                                                                     set-up capabilities and procedures,
                                             functional connections among security                                                                         Atmospheric Administration (NOAA),
                                                                                                     demonstration harnesses, environmental
                                             platform components                                                                                           Commerce.
                                                                                                     and safety conditions for use, integrated
                                               2. Support for development and                        platform user instructions, and                       ACTION: Notice.
                                             demonstration of the Securing Picture                   demonstration plans and scripts
                                             Archiving and Communication System                                                                            SUMMARY:    The Department of
                                                                                                     necessary to demonstrate the desired
                                             (PACS) Cybersecurity for the healthcare                                                                       Commerce, as part of its continuing
                                                                                                     capabilities. Each participant will train
                                             sector use case in NCCoE facilities                                                                           effort to reduce paperwork and
                                                                                                     NIST personnel, as necessary, to operate
                                             which will be conducted in a manner                                                                           respondent burden, invites the general
                                                                                                     its product in capability demonstrations
                                             consistent with the following standards                                                                       public and other Federal agencies to
                                                                                                     to the healthcare community. Following
                                             and guidance: FIPS 200, FIPS 201, SP                                                                          take this opportunity to comment on
                                                                                                     successful demonstrations, NIST will
                                             800–53 and FIPS 140–2, SP 800–30, SP                                                                          proposed and/or continuing information
                                                                                                     publish a description of the security
                                             800–37, SP 800–39, SP 800–41, SP 800–                                                                         collections, as required by the
                                                                                                     platform and its performance
                                             52, SP 800–57, SP 800–63–3, SP 800–66,                                                                        Paperwork Reduction Act of 1995.
                                                                                                     characteristics sufficient to permit other
                                             SP 800–77, SP 800–95, SP 800–144, SP                    organizations to develop and deploy                   DATES: Written comments must be
                                             800–146, SP 800–171, SP 800–181, ISO                    security platforms that meet the security             submitted on or before July 9, 2018.
amozie on DSK3GDR082PROD with NOTICES




                                             12052:2011 Health Informatics—Digital                   objectives of the Securing Picture                    ADDRESSES: Direct all written comments
                                             Imaging and Communication in                            Archiving and Communication System                    to Jennifer Jessup, Departmental
                                             Medicine (DICOM) including Workflow                     (PACS) Cybersecurity for the healthcare               Paperwork Clearance Officer,
                                             and Data Management, AAMI TIR57,                        sector use case. These descriptions will              Department of Commerce, Room 6616,
                                             ANSI/AAMI/IEC 80001–1:2010, IEC                         be public information.                                14th and Constitution Avenue NW,
                                             Technical Report 80001–2–1, IEC                            Under the terms of the consortium                  Washington, DC 20230 (or via the
                                             Technical Report 80001–2–2, internet                    CRADA, NIST will support                              internet at pracomments@doc.gov).


                                        VerDate Sep<11>2014   17:39 May 08, 2018   Jkt 244001   PO 00000   Frm 00018   Fmt 4703   Sfmt 4703   E:\FR\FM\09MYN1.SGM   09MYN1



Document Created: 2018-05-09 03:17:16
Document Modified: 2018-05-09 03:17:16
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice.
DatesCollaborative activities will commence as soon as enough
ContactAndrea Arbelaez via email to [email protected]; by telephone 301-975-0214; or by mail to National Institute of Standards and Technology, NCCoE, 9700 Great Seneca Highway, Rockville, MD 20850. Additional details about the healthcare sector program are available at https://nccoe.nist.gov/projects/use- cases/health-it/pacs.
FR Citation83 FR 21272 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR