Medical Device Software Cyber Risk Assessment Template
1. Device Identification
Device Name
Model
Manufacturer
Software Version
Description
2. Intended Use & Network Connectivity
Intended Use
Network/Connectivity Interfaces
3. Asset Inventory
Asset
Type
Description
4. Threat Identification
Threat Source
Threat Event
Affected Asset
5. Vulnerability Identification
Vulnerability
Description
Affected Asset
6. Risk Analysis
Risk Description
Likelihood
Impact
Risk Level
Low
Medium
High
Low
Medium
High
Low
Medium
High
Low
Medium
High
7. Mitigation Measures
Risk
Mitigation Strategy
Status
Implemented
Planned
Not Implemented
Implemented
Planned
Not Implemented
8. Residual Risk Evaluation
Residual Risks & Justification
9. Review & Approval
Prepared by
Date
Approved by
Date