Bill Hansen
Registered
As I'm trying to bring cybersecurity concerns into our safety risk management process, I am struggling with the right way to capture Loss of Confidentiality. Has anyone come up with a solid solution?
I think the addition of "unreasonable psychological stress" in 14971:2019 (see A.2.3) provides a good path. This is supported by 24971's example (table F.1), linking "loss of data confidentiality" to "psychological stress", as well as "deterioration of health"... but the latter has many options in current Harms Lists.
So, to add "psych stress" to a Harms List, using a typical 5-point Severity scale, I have this thought. Someone tell me if this is sound, or something else.
I don’t see a need for a Severity 5.
This remains consistent with the FDA’s definition of “serious harm”, aligning with S=3 and above: medical intervention is required.
So we have to keep people safe... AND sane!
I think the addition of "unreasonable psychological stress" in 14971:2019 (see A.2.3) provides a good path. This is supported by 24971's example (table F.1), linking "loss of data confidentiality" to "psychological stress", as well as "deterioration of health"... but the latter has many options in current Harms Lists.
So, to add "psych stress" to a Harms List, using a typical 5-point Severity scale, I have this thought. Someone tell me if this is sound, or something else.
- Unreasonable Psychological Stress, Minor; Severity 2 – patient or user is aware of issue (such as loss of PII), causes stress, distraction. No professional intervention is required.
- UPS, Major; Severity 3 – issue causes patient/user stress, requiring professional intervention, such as counseling. Temporary condition.
- UPS, Critical; Severity 4 – issue causes patient/user stress resulting in long-term/permanent effects (PTSD or similar); professional intervention, including psychiatric treatment, required for quality of life.
I don’t see a need for a Severity 5.
This remains consistent with the FDA’s definition of “serious harm”, aligning with S=3 and above: medical intervention is required.
So we have to keep people safe... AND sane!