-
Notifications
You must be signed in to change notification settings - Fork 45
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add Software Level of Support property to Software Package #561
Comments
Thanks to the participants of the Asia team for point this out. See the minutes from 2023-11-27 for context. |
One issue with adding this to the model is it is time dependent whereas other SBOM package information is static. We currently have an end of life date which provides the information to generate this "on the fly". Ideally, we could change the FDA requirements to allow the end of life date. |
We discussed this issue in the December 5th tech call and agree this should be high priority to include. The EU CRA is coming soon and will also require suppliers to declare support times. There are a few ways this might be implemented:
We agreed to start with thisissue at the tech call next week to see if we could model it in a reasonable amount of time. If not, we will host a one-off meeting to get this completed before bringing it back to the tech team for approval. |
Since we already have a validUntilTime property, we could implement 2 above and amend the I would not be in favor of having both a |
Working through the following references to align with what the industry expects: |
@kestewart - can you lead a discussion on this when you're back? Perhaps on the 19 March call? |
From the two docs that @kestewart posted above, these are names for stages in tech/device life cycle: Managing Legacy Technology Security (HIC-MaLTS) (pp. 3-4, 8-9):
IMDRF Principles and Practices for the Cybersecurity of Legacy Medical Devices (p. 10):
|
This was added in #628 The set that was agreed on is in: What is being proposed to be added? |
In the call, Gary noted that deployment should be a specific support type. Gary to create a PR. |
@goneall they are. Thank you. |
Resolved with PR #668 |
The Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions section 4b states:
We currently do not have a field to map the software level of support provided.
The text was updated successfully, but these errors were encountered: