International Standards

Certification & Approval
N° 01
IEC 81001-5-1
Health Software Product Lifecycle SecurityHealth software, Security activities in the product life cycle
Global · IEC

Overview

An international standard that defines security activities to be performed throughout the entire lifecycle of health software. It requires security to be built in from the design phase through to decommissioning.

Recommended Tests

  • Threat modeling and security requirements definition
  • Security design verification (SAST/DAST)
  • Vulnerability assessment and penetration testing
  • SBOM creation and verification
  • Security update process review
Threat ModelingSAST/DASTVulnerability AssessmentSBOM
N° 02
UL 2900-1 / 2900-2-1
Software Cybersecurity for Network-Connectable ProductsSoftware Cybersecurity for Network-Connectable Products
USA · UL

Overview

A U.S. standard for evaluating cybersecurity requirements of network-connectable products. UL 2900-1 covers general requirements, while UL 2900-2-1 addresses requirements specific to medical devices.

Series Components

  • UL 2900-1 General Network-Connectable Products
  • UL 2900-2-1 Medical Device Specific

Recommended Tests

  • Fuzz testing (all network interfaces)
  • Static source code analysis (SAST)
  • Known vulnerability (CVE) matching
  • SBOM-based software composition analysis
  • Access control and authentication mechanism testing
Fuzz TestingSASTCVE MatchingSBOM
N° 03
EN 18031-1/2/3
EU Radio Equipment Cybersecurity RequirementsCommon security requirements for radio equipment
EU · ETSI / CEN-CENELEC

Overview

A harmonized European standard specifying mandatory cybersecurity requirements under EU Radio Equipment Directive (RED) Article 3(3)(d)(e)(f). Compliance becomes mandatory for products placed on the EU market from August 2025.

Series Components

  • EN 18031-1 Network Security
  • EN 18031-2 Privacy Protection
  • EN 18031-3 Financial Fraud Prevention

Recommended Tests

  • Access control and authentication mechanism testing
  • Secure communication channel (TLS/DTLS) verification
  • Software update security mechanism inspection
  • Stored data and transmitted data protection verification
  • Vulnerability disclosure and patch management process review
REDAccess ControlEncryption VerificationUpdate SecurityPrivacy Protection
N° 04
ETSI EN 303 645
Cyber Security for Consumer IoTCyber Security for Consumer Internet of Things
EU · ETSI

Overview

A European standard that defines security baselines for consumer IoT devices. It specifies 13 mandatory security provisions including prohibition of default passwords, vulnerability disclosure policies, and software update mechanisms.

Recommended Tests

  • Default password usage verification
  • Vulnerability Disclosure Policy (VDP) establishment check
  • Software update mechanism verification
  • Data protection (encryption) testing for stored and transmitted data
  • Attack surface minimization and unnecessary port inspection
IoT SecurityVDPUpdate SecurityEncryption Verification

Reference Frameworks

Test Item Derivation
N° 01
OWASP Top 10
Top 10 Web Application Security RisksOpen Worldwide Application Security Project
Global · OWASP

Overview

A project that catalogs the 10 most frequently occurring security vulnerabilities in web applications. Applied to web-based management interfaces of medical devices, cloud integration APIs, and similar components.

Recommended Tests

  • Injection attack (SQL, OS, LDAP) testing
  • Authentication and session management flaw inspection
  • Sensitive data exposure verification
  • Security misconfiguration assessment
  • API security and SSRF testing
Web Penetration TestingAPI SecurityAuthentication AuditDAST
N° 02
CWE Top 25
Most Dangerous Software WeaknessesCommon Weakness Enumeration · Most Dangerous Software Weaknesses
Global · MITRE

Overview

The 25 most dangerous software weakness types as identified by MITRE. During source code analysis, defects are classified and prioritized based on this list.

Recommended Tests

  • Buffer overflow and memory safety inspection
  • Improper input validation (CWE-20) analysis
  • Path traversal and command injection testing
  • Improper privilege management inspection
  • Static analysis (SAST) based CWE mapping
SASTMemory SafetyInput ValidationCode Analysis
N° 03
IEC TR 60601-4-5
Safety Related Technical Security SpecificationsMedical equipment - Guidance and interpretation, Safety related technical security specifications
Global · IEC (TR)

Overview

A technical report that interprets and maps the security capability requirements of IEC 62443-4-2, an industrial control system security standard, to medical electrical equipment. Although guidance rather than a normative standard, it allows the security level (SL 1-4) of a medical device to be stated quantitatively, and is used as the basis for security requirements when addressing IEC 81001-5-1.

Recommended Tests

  • Identification and authentication control (FR1) testing
  • Use control and privilege management (FR2) inspection
  • System integrity (FR3) verification
  • Data confidentiality (FR4) and restricted data flow (FR5) testing
  • Timely response to events (FR6) and resource availability (FR7) inspection
  • Security level (SL-C) determination and gap analysis
IEC 62443-4-2Security Level (SL)7 Foundational RequirementsSafety-Security Linkage
N° 04
NIST SP 800-115
Technical Guide to Information Security TestingTechnical Guide to Information Security Testing and Assessment
USA · NIST

Overview

A methodology guide for information security testing and assessment published by NIST. It formalizes the full process of penetration testing and vulnerability assessment from planning through reporting, and serves as the basis for the objectivity and repeatability of our testing procedures.

Penetration Testing Phases

  • Planning Scope and rules of engagement, prior authorization
  • Discovery Target identification and vulnerability analysis
  • Attack Vulnerability validation and privilege escalation
  • Reporting Results consolidation and remediation guidance

Recommended Tests

  • Ruleset and system configuration review, log analysis
  • Network discovery, port and service identification
  • Vulnerability scanning and wireless scanning
  • Password cracking and penetration testing
Penetration Testing MethodologyFour PhasesVulnerability ValidationPlanning & Reporting
N° 05
CIS Benchmarks
Security Configuration Baselines for Network DevicesCIS Benchmarks for Network Devices
Global · CIS

Overview

Security configuration baselines published by the Center for Internet Security. The network device benchmarks define vendor-specific recommended settings on an item-by-item basis, separated into a Level 1 essential profile and a Level 2 hardened profile.

Target Devices

  • Routers and switches (Cisco IOS and others)
  • Firewalls (Palo Alto, Fortinet, Check Point and others)
  • Wireless controllers and VPN appliances

Recommended Tests

  • Management access control, default account and password inspection
  • AAA authentication configuration and privilege separation verification
  • Unnecessary service and port deactivation check
  • Logging and NTP time synchronization inspection
  • Routing protocol authentication and ACL review
Configuration BaselineNetwork DevicesLevel 1/2Configuration Audit

Korea · Statutory Assessment Guides

Domestic Compliance
N° 01
CIIP Act §9
Vulnerability Analysis & Assessment for Critical InfrastructureAct on the Protection of Information and Communications Infrastructure
Korea · MSIT / KISA

Overview

A statutory vulnerability analysis and assessment that organizations designated as critical information and communications infrastructure must perform annually under Article 9 of the Act on the Protection of Information and Communications Infrastructure. Technical, administrative, and physical vulnerabilities are inspected against the KISA Detailed Guide for Technical Vulnerability Analysis and Assessment. WiseLab performs technical vulnerability inspection and penetration testing against the items in that guide and delivers the test results.

Assessment Domains

  • Unix / Windows servers, DBMS
  • Network equipment and security appliances
  • Web applications, endpoints
  • Control systems and connected IoT facilities

Services Provided

  • Asset identification and criticality rating
  • Technical vulnerability inspection per the detailed guide
  • Administrative and physical vulnerability inspection
  • Penetration testing
  • Remediation planning and prior-year implementation review
CIIP ActAnnual StatutoryPenetration TestingRemediation Planning
N° 02
EFT Supervisory Reg.
Vulnerability Analysis & Assessment for Financial SystemsElectronic Financial Transactions Act · Supervisory Regulation
Korea · FSI

Overview

A vulnerability analysis and assessment performed by financial institutions and electronic financial businesses under the Electronic Financial Transactions Act and its Supervisory Regulation, applying the assessment criteria published by the Financial Security Institute. It covers customer-facing channels such as internet banking, mobile applications, and open banking APIs, as well as internal business systems. WiseLab performs technical inspection and penetration testing against those criteria and delivers the test results.

Assessment Domains

  • Internet banking and mobile banking applications
  • Open banking and financial APIs
  • Servers, network equipment, security appliances, DBMS
  • Internal network business systems and endpoints

Services Provided

  • Customer channel penetration testing, web and mobile app assessment
  • Financial API authentication, authorization, and transaction integrity verification
  • Infrastructure technical vulnerability inspection
  • Internal network penetration testing based on attack scenarios
  • Remediation planning and re-assessment
EFT Supervisory RegulationPenetration TestingFinancial API SecurityMobile App AssessmentRemediation Planning