User:Shawndouglas/sandbox/sublevel45
Imagine a medical device manufacturer (which happens to incorporate laboratories, but that's not the main point here). A medical device manufacturer works in a highly regulated industry that not just asks but demands quality from the manufactured medical devices. As many such devices are increasingly electronic—and even network-enabled—it's imperative that cybersecurity is considered in their design and use.[1] As David Jensen of MasterControl noted in 2017: "The technologies that elevate the quality of life for patients can be used by cyber actors to undermine both the manufacturing organization and the products themselves. This means cybersecurity is as much a quality issue as it is a security issue."[2]
Note that Jensen related "cybersecurity" and "quality" together, which naturally leads to a discussion of the quality management system (QMS). A QMS is "a set of related and interacting elements that organizations use to direct and control how quality policies are implemented and quality objectives are achieved."[3] Those elements include, but are not limited to, documented processes, management models, business strategies, human capital, and information technology. Not only does the QMS help guide the implementation and achievement of organizational policy and objectives for resource management and personnel, but also it prompts an organization to focus on the core elements of quality management within its products and services: planning, control, assurance, and improvement. And just as the development and use of a QMS is often driven by standards (e.g., ISO/IEC 17025:2017 and ISO 13485:2016), the QMS often drives the organization to adopt other standards as part of bringing quality to the organization. Using our medical device manufacturer as an example, their QMS may direct them to use the ANSI/CAN/UL 2900-1 standard for ensuring medical device cybersecurity protection.[4]
Not only is the QMS vital to medical device manufacturers[2][5][6][7], but also the QMS plays an important role in most any laboratory's operations.[8][9] And in the laboratory, a quality assurance officer or manager is responsible for helping develop and maintain the laboratory's QMS, which optimally will address the importance of cybersecurity in meeting the laboratory’s goals. But the connection between a laboratory's quality assurance officer and cybersecurity is sadly not well represented in the cloud computing era. Look through the job descriptions on online job boards for quality assurance officers and you will rarely find the word "security" mentioned. Sure, the relationship between "quality" and "security" gets discussed in the context of modern software development[10], but what about within the context of a laboratory's operational quality and the people who drive it forward?
In a 2019 journal article for Lab Manager magazine, Sandia National Laboratories' chief information officer Carol Jones stated that "[c]ybersecurity is not just a technology problem; it is a people, process, and knowledge problem."[11] While this is an accurate statement, shouldn't cybersecurity also be a quality problem for a laboratory? Yes, well-trained people, vetted processes, and relevant and timely knowledge is required to ensure secure operations, but quality management and assurance—which incorporates that training, SOPs, and knowledge—should also be part of that equation. One could argue that the responsibilities of a quality assurance officer or manager are already numerous and weighty. But shouldn't that person at least have a modicum of understanding about how well-implemented IT and software security in the lab correlates to improved quality assurance outcomes?[12]
At this juncture, several questions must be asked about the quality assurance officer or manager in a laboratory operating in the 2020s:
- What is the importance of the quality assurance officer (QAO), and do they understand cybersecurity?
- How does the QAO help ensure quality of operations with security as a managed service?
- How do standard operating procedures (SOPs), security audits, and other elements of a QMS positively affect quality assurance by addressing cybersecurity and cloud hosting processes?
The importance of a QAO and their security knowledge
First, the definition of what a QAO does will largely vary from company to company. However, turning to Bartram and Ballance's 1996 guide Water Quality Monitoring, the author's describe a quality assurance officer as someone "to liaise with management, to manage data archives, to conduct regular audits and reviews of the QA system, and to report on any QA issues to the program or institution manager."[13] They add that the QAO is also "responsible for regularly inspecting all aspects of the [record keeping] system to ensure staff compliance, for reporting on such inspections and audits to management, and for recommending improvements."[13] But what of a more modern definition? Turning to ISO 9000, we get a bland and non-informative definition of quality assurance itself: "part of quality management focused on providing confidence that quality requirements will be fulfilled."[14] By extension, we then get "a person responsible for providing confidence that requirements for organizational quality are fulfilled." This is a broad description, sadly. However, pulling from Bartram and Ballance, the ISO, and other sources[15][16], we could go with something like:
A quality assurance officer (QAO) is an individual responsible for ensuring organizational quality through the regular management, monitoring, review, and auditing of documentation, record systems, data, and processes as they relate to organizational quality and compliance frameworks and initiatives, while also reporting timely results, making recommendations based on those results, and assisting with training staff on approved recommendations.
Given that definition, does the average QAO need to understand at least the basics of cybersecurity? That's arguable, to be sure. After all, there are job positions such as the "cybersecurity quality and compliance officer" and the like[15], with an individual who works directly with an IT department and its cybersecurity team to ensure all mandatory laws and regulatory requirements are being adhered to, much in the same way a QAO does but on a broader organizational basis. But what about the laboratory realm? Major laboratories with significant resources may have these sorts of positions, but smaller, independent labs may not. In that case, laboratory personnel will often wear many hats, including "the tech person" or "laboratory systems engineer." (See Joe Liscouski's discussion of the "laboratory systems engineer" in his 2020 guide Laboratory Technology Planning and Management: The Practice of Laboratory Systems Engineering for more on this topic.[17]) However, given that the security surrounding an organization's electronic efforts is vital to maintaining quality operations, and also given that—hopefully—cybersecurity efforts are documented and trained upon, it's not that far a leap to suggest that the laboratory QAO should have a rudimentary understanding of IT systems and how they are secured. If cybersecurity is interwoven into the laboratory culture, including quality management, the tech-savvy QAO will be a boon to the overall quality assurance process.
The QAO and managed security services
Where does a QAO and an MSS intersect in the lab? Judging by the previous statement that the QAO may need to review organizational documentation and training material regarding cybersecurity—and even audit or assess personnel on their use of that documentation and training—we can see deduce that a QAO may be required to audit the effectiveness of any implemented MSS, or at least the documentation and processes related to the MSS. Again, it's likely in mid- to large size organizations this responsibility will fall upon the shoulders of an IT lead or IT quality officer. However, these resources may not be readily available in some laboratory settings. If those resources aren't available, the QAO may be required to know more than they expected about what managed security services entail. They won't need to be MSS experts, but as the nature of computing in the laboratory continues to evolve, having laboratory staff with relevant knowledge of automation, data management systems, and even the cloud is increasingly vital.[17]
The QMS and cybersecurity
In 2019, scientific and business consultancy Brevitas brought up the challenges of addressing cybersecurity in laboratories and other settings, noting evolving guidance that strives to address the business policies, security controls, informatics systems, and security monitoring required to better ensure the integrity and security of electronic records and data. They are one of a handful of consultancies that have publicly tied these types of standard-driven cybersecurity measures directly to the QMS[18]:
The challenge is in ensuring that these measures are effectively integrated into the existing processes outlined in the organization’s quality management system (QMS). Consideration needs to be given to first integrating cybersecurity into risk and/or criticality assessments, then downstream into system security testing during qualification and/or validation activities. As the technological landscape evolves, organizations must be more effective in their implementation of cybersecurity measures to ensure the safety of their electronic records and data. These measures must be considered as part of the QMS for all activities involved in the lifecycle of a computerized system.
As has been previously mentioned, this type of philosophy is already woven into the fabric of medical device regulation and standardization, with 21 CFR 820 on quality system regulation, ISO 13485:2016 on quality management systems, and ANSI/CAN/UL 2900 on ensuring medical device security driving how medical device cybersecurity is addressed in the manufacturer's quality management system.[7][19][20][21][22] And it may be even easier for medical device manufacturers—as well as other laboratory types—to compile, organize, disseminate, and train upon cybersecurity risk analysis data and procedural documentation with the help of an electronic QMS.[2] However, we can turn to some other businesses who have included security standards in their quality management system. Technology consultancy Konsolute has discussed why it chose to integrate ISO 27001 on information security management (and the information security management system or ISMS) into its business processes and the development of its electronic QMS, noting benefits of improved compliance, lower security risk, improved financial savings, improved reputation, and more new business.[23]
As it turns out, the ISMS and ISO 27001 have a bit in common with the QMS and ISO 9001, primarily with the goal of improving quality within the organization. Here again we see the link between a focus on cybersecurity and ensuring quality within an organization.[24][25] Senior associate Nikita Patel of Schellman & Company highlighted this association in 2017, saying that an organization "achieving this dual certification of an ISO 9001 and ISO 27001 can prove incredibly useful—in doing so, an organization can simultaneously demonstrate an organization’s ability and commitment to information security risk management, while also validating their dedication to the optimal delivery of their quality products and services."[25] From addressing anything from scoping, leadership, human resources support, and document management to internal auditing, measurement and monitoring, management review, and continual improvement, both the ISMS, focused on information security, and QMS, focused on organizational quality, improve the overall quality of an organization and its efforts.
The QAO in the context of these three points
Where does this all place the quality assurance officer in the scope of laboratory quality and information security? Whether it's managed security services, private or public cloud services, in-house networking, or a mix of all these, the modern laboratory is a technology-driven business requiring modern approaches to addressing the risks that technology carries with it. An on-site IT staff may handle many of the details associated with those efforts, but the QAO of the 2020s needs to also be familiar with how that technology works and how it impacts organizational quality initiatives. The QAO will interact with the lab's QMS, and perhaps even the ISMS if one separately exists. Ideally cybersecurity policy and procedure is already woven into the various elements of the QMS, or, worst case, the lab doesn't have much of a cybersecurity policy. This is where the QAO of today's lab must shine, "ensuring organizational quality through the regular management, monitoring, review, and auditing of documentation, record systems, data, and processes as they relate to organizational quality and compliance frameworks and initiatives." That means also understanding how managed security services and cloud services operate. It's perhaps a tall ask, but in today's competitive laboratory environment, the tech-savvy QAO is more important than ever.
References
- ↑ Nayyar, S. (22 December 2020). "The Unique Threats Posed By Medical IoT Devices And What To Do About Them". Forbes. https://www.forbes.com/sites/forbestechcouncil/2020/12/22/the-unique-threats-posed-by-medical-iot-devices-and-what-to-do-about-them/. Retrieved 21 August 2021.
- ↑ 2.0 2.1 2.2 Jensen, D. (3 June 2017). "How an Electronic Quality Management System Helps With Cybersecurity". MasterControl. https://www.mastercontrol.com/gxp-lifeline/how-an-electronic-quality-management-system-helps-with-cybersecurity/. Retrieved 21 August 2021.
- ↑ Shoemaker, D.; Sigler, K. (2014). Cybersecurity: Engineering a Secure Information Technology Organization. Cengage Learning. pp. 62–63. ISBN 9781285169903. https://books.google.com/books?id=b1s8AwAAQBAJ&pg=PA62.
- ↑ Wirth, A.; Gates, C.; Smith, J. (2020). Medical Device Cybersecurity for Engineers and Manufacturers. Artech House. pp. 23–24. ISBN 9781630818159. https://books.google.com/books?id=oawCEAAAQBAJ&pg=PA23.
- ↑ Therapeutic Goods Administration (March 2021). "Medical device cyber security guidance for industry" (PDF). Commonwealth of Australia. https://www.tga.gov.au/sites/default/files/medical-device-cyber-security-guidance-industry.pdf. Retrieved 21 August 2021.
- ↑ "Risk Management Best Practices for Cybersecurity Compliance". AssurX Blog. AssurX, Inc. 30 January 2017. https://www.assurx.com/risk-management-cybersecurity-compliance/. Retrieved 21 August 2021.
- ↑ 7.0 7.1 "Cybersecurity & Quality Management System Integration". Apraciti. https://apraciti.com/cybersecurity-quality-management-system-integration/. Retrieved 21 August 2021.
- ↑ World Health Organization (2011). Laboratory Quality Management System Handbook. World Health Organization. ISBN 9789241548274. https://www.who.int/ihr/publications/lqms/en/.
- ↑ United States Geological Survey. "Quality Management System for USGS Laboratories". United States Geological Survey. https://www.usgs.gov/about/organization/science-support/office-science-quality-and-integrity/quality-management-system. Retrieved 21 August 2021.
- ↑ Worrall, J. (18 August 2020). "Why Quality & Security Both Matter in Software". DarkReading. https://www.darkreading.com/vulnerabilities---threats/why-quality-and-security-both-matter-in-software/a/d-id/1338649. Retrieved 21 August 2021.
- ↑ Tulsi, B.B. (4 September 2019). "Greater Awareness and Vigilance in Laboratory Data Security". Lab Manager. https://www.labmanager.com/business-management/greater-awareness-and-vigilance-in-laboratory-data-security-776. Retrieved 21 August 2021.
- ↑ Hamidovic, H. (2012). "Fundamental Concepts of IT Security Assurance". ISACA Journal 2: 45–9. https://www.isacajournal-digital.org/isacajournal/2012vol2?article_id=1078418&pg=45.
- ↑ 13.0 13.1 Bartram, J.; Ballance, R., ed. (2020). Water Quality Monitoring: A practical guide to the design and implementation of freshwater quality studies and monitoring programmes. CRC Press. p. 218. ISBN 9780419223207. https://books.google.com/books?id=5PQCEAAAQBAJ&pg=PA218.
- ↑ "ISO 9000:2015(en) Quality management systems — Fundamentals and vocabulary". ISO. 2015. https://www.iso.org/obp/ui/#iso:std:iso:9000:en. Retrieved 21 August 2021.
- ↑ 15.0 15.1 Genesis IT&T (10 May 2021). "Cybersecurity Quality and Compliance Officer - 6 Month Contract". Seek. Archived from the original on 21 August 2021. https://web.archive.org/web/20210524220443/https://www.seek.com.au/job/52226409?type=standard. Retrieved 21 August 2021.
- ↑ "Quality Control Officer - What They Do". Zippia. https://www.zippia.com/quality-control-officer-jobs/what-does-a-quality-control-officer-do/. Retrieved 21 August 2021.
- ↑ 17.0 17.1 Liscouski, J. (December 2020). "Laboratory Technology Planning and Management: The Practice of Laboratory Systems Engineering".
- ↑ "Cybersecurity Response". Brevitas. 2019. https://brevitas.us/cybersecurity-response/. Retrieved 21 August 2021.
- ↑ Lincoln, J.E. (17 April 2017). "Cybersecurity - Buzzword or Serious Safety Concern?". IVT Network. https://www.ivtnetwork.com/article/cybersecurity-buzzword-or-serious-safety-concern. Retrieved 21 August 2021.
- ↑ Heyl, J. (October 2017). "Overview of UL 2900 - Medical Device Cybersecurity Workshop" (PDF). UL. https://www.cybersecuritysummit.org/wp-content/uploads/2017/10/4.00-Justin-Heyl.pdf. Retrieved 21 August 2021.
- ↑ "UL 2900: A Cybersecurity aid for industry and regulators" (PDF). UL. 2019. https://www.fda.gov/media/123068/download. Retrieved 21 August 2021.
- ↑ "ISO 13485:2016 Medical devices — Quality management systems — Requirements for regulatory purposes". ISO. March 2016. https://www.iso.org/standard/59752.html. Retrieved 21 August 2021.
- ↑ "Cybersecurity of the future: Why we include ISO 27001 as standard in our Quality Management System". Konsolute. 30 April 2021. https://www.konsolute.com/blog/iso-27001-cybersecurity-quality-management/. Retrieved 21 August 2021.
- ↑ "Information Security Management System (ISMS)". CVG Strategy. 2020. https://cvgstrategy.com/information-security-management-system/. Retrieved 21 August 2021.
- ↑ 25.0 25.1 Patel, N. (16 October 2017). "ISO 9001 and 27001 – The Relationship". Schellman Blog. Schellman & Company. https://www.schellman.com/blog/iso-9001-and-27001-the-relationship. Retrieved 21 August 2021.