Appendix 3. Cybersecurity
This appendix is intended for the IT network responsible at the organization where
the displaying unit is used. It contains technical information regarding the setup of the
IT network and the devices connected to the displaying unit. It also contains information
regarding the types of data contained in and transmitted from the displaying unit.
The displaying unit is of medium security risk (according to NIST) as:
•
The displaying unit does not allow any input from external devices (except from Ambu
visualization devices and secured software updates).
•
Essential functionality is secured in case of network problems.
Appendix 3.1. Network Setup
When preparing the network for connection to the displaying unit, the following should
be considered:
Overview of the existing ports and their communication protocols
Item
Wireless
communication
LAN communication
Access test
Network adaptor
configuration
Re-routing
PACS servers
Ports
Note: There are no open ports, the device firewall only accepts TCP responses for DICOM and replies to
ICMP ping requests.
54
Standards used
IEEE 802.11
IEEE 802.3
IEEE 802.3ab
IEEE 802.3az
PICMG3.1
ICMP/ping
DHCP
Static IP
DICOM
Comments
The device uses a WPA_Supplicant
to support WPA2/WPA3 Wireless
communication as TKIP and CCMP.
The authentication and integrity of
the communication is provided by the
underlying FIPS 140-2 compliant chipset
wireless driver. Wi-Fi option supports
WPA2/WPA3 Enterprise.
The device uses a standard Gigabit Ethernet
controller supporting a 1000base-T interface.
Allowing ease-of-discovery for hospital IT
infrastructure.
Static IP address (IPv4) is configurable in
the GUI.
The device does not support re-routing
traffic from Wi-Fi to LAN or vice versa,
therefore the device cannot act as a NAT
(Network Address Translation) gateway.
To support a broad range of network
infrastructures and PACS servers, the device
supports DICOM without CMS (Cryptographic
Message Syntax) encryption for transporting
photo(s) and video(s) to the PACS server.
There are no open ports, the device firewall
only accepts TCP responses for DICOM and
replies to ICMP ping requests.