Test results are delivered precisely mapped to the items and evidence formats required by each regulatory authority. They can be used directly as regulatory submission documents without additional processing.
An international standard that defines security activities to be performed throughout the entire lifecycle of health software. It requires security to be built in from the design phase through to decommissioning.
A U.S. standard for evaluating cybersecurity requirements of network-connectable products. UL 2900-1 covers general requirements, while UL 2900-2-1 addresses requirements specific to medical devices.
A harmonized European standard specifying mandatory cybersecurity requirements under EU Radio Equipment Directive (RED) Article 3(3)(d)(e)(f). Compliance becomes mandatory for products placed on the EU market from August 2025.
A European standard that defines security baselines for consumer IoT devices. It specifies 13 mandatory security provisions including prohibition of default passwords, vulnerability disclosure policies, and software update mechanisms.
A project that catalogs the 10 most frequently occurring security vulnerabilities in web applications. Applied to web-based management interfaces of medical devices, cloud integration APIs, and similar components.
The 25 most dangerous software weakness types as identified by MITRE. During source code analysis, defects are classified and prioritized based on this list.
A technical report that interprets and maps the security capability requirements of IEC 62443-4-2, an industrial control system security standard, to medical electrical equipment. Although guidance rather than a normative standard, it allows the security level (SL 1-4) of a medical device to be stated quantitatively, and is used as the basis for security requirements when addressing IEC 81001-5-1.
A methodology guide for information security testing and assessment published by NIST. It formalizes the full process of penetration testing and vulnerability assessment from planning through reporting, and serves as the basis for the objectivity and repeatability of our testing procedures.
Security configuration baselines published by the Center for Internet Security. The network device benchmarks define vendor-specific recommended settings on an item-by-item basis, separated into a Level 1 essential profile and a Level 2 hardened profile.
A statutory vulnerability analysis and assessment that organizations designated as critical information and communications infrastructure must perform annually under Article 9 of the Act on the Protection of Information and Communications Infrastructure. Technical, administrative, and physical vulnerabilities are inspected against the KISA Detailed Guide for Technical Vulnerability Analysis and Assessment. WiseLab performs technical vulnerability inspection and penetration testing against the items in that guide and delivers the test results.
A vulnerability analysis and assessment performed by financial institutions and electronic financial businesses under the Electronic Financial Transactions Act and its Supervisory Regulation, applying the assessment criteria published by the Financial Security Institute. It covers customer-facing channels such as internet banking, mobile applications, and open banking APIs, as well as internal business systems. WiseLab performs technical inspection and penetration testing against those criteria and delivers the test results.